MidnightBSD

Advisories for myfpcu

CVE-2017-9568 MEDIUM

The financial-plus-mobile-banking/id731070564 app 3.0.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
myfpcu financial_plus_mobile_banking 3.0.3