Skip to content
appaloosa scout logo main rounded
fr en
MEDIUM 5.9

CVE-2017-5915

The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
emirates_nbd_bank_p.j.s.c emirates_nbd iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd:3.10.0:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd:3.10.1:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd:3.10.2:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd:3.10.3:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd:3.10.4:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd_ksa iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd_ksa:2.0.0:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd_ksa iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd_ksa:2.0.1:*:*:*:*:iphone_os:*:*
emirates_nbd_bank_p.j.s.c emirates_nbd_ksa iOS cpe:2.3:a:emirates_nbd_bank_p.j.s.c:emirates_nbd_ksa:2.1.0:*:*:*:*:iphone_os:*:*
View on NVD ↗