CVE Database
/

CVE-2018-16179

Back to search

CVE-2018-16179

Published: Jan 9, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

VendorProductVersions

Mizuho Bank, Ltd.

Mizuho Direct App for Android

affected
version 3.13.0 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now