RSS   Vulnerabilities for
'Bharat interface for money (bhim)'
   RSS

2018-08-24
 
CVE-2017-9821

CWE-798
 

 
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.

 
 
CVE-2017-9820

CWE-287
 

 
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.

 
 
CVE-2017-9819

CWE-287
 

 
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.

 
 
CVE-2017-9818

CWE-521
 

 
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.

 


Copyright 2024, cxsecurity.com

 

Back to Top