The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://medium.com/%40chronic_9612/follow-up-76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-64185035029f | |
http://www.securityfocus.com/bid/98308 | third party advisory vdb entry |
http://www.kb.cert.org/vuls/id/276408 | third party advisory us government resource |