CVE-2014-7589

Publication date

2014-10-20 10:00:00

Family

certcc

State

PUBLISHED

Description

The Industrial and Commercial Bank of China (ICBC) Banking (aka com.icbc.android) application 2.40 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.