Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-23533 | 1 Unionpayintl | 1 Union Pay | 2022-11-04 | 5.0 MEDIUM | 7.5 HIGH |
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL. | |||||
CVE-2020-36284 | 1 Unionpayintl | 1 Union Pay | 2021-04-09 | 5.0 MEDIUM | 7.5 HIGH |
Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL. | |||||
CVE-2020-36285 | 1 Unionpayintl | 1 Union Pay | 2021-04-09 | 5.0 MEDIUM | 7.5 HIGH |
Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL. |