CVE-2017-9821

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
24/08/2018
Last modified:
01/11/2018

Description

The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:npci:bharat_interface_for_money_\(bhim\):1.3:*:*:*:*:android:*:*