PT-2021-11992 · Union Pay · Union Pay

Published

2021-04-06

·

Updated

2021-04-09

·

CVE-2020-36285

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Union Pay versions up to 3.3.12
Description: The issue allows attackers to shop for free in merchants' websites and mobile apps by generating a crafted authentication code (MAC) based on a secret key which is NULL. This is due to an improper verification of cryptographic signature.
Recommendations: For Union Pay versions up to 3.3.12, update to a version that properly verifies cryptographic signatures to prevent exploitation. As a temporary workaround, consider implementing additional validation checks for authentication codes to minimize the risk of exploitation.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36285

Affected Products

Union Pay