PT-2021-11992 · Union Pay · Union Pay
Published
2021-04-06
·
Updated
2021-04-09
·
CVE-2020-36285
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Union Pay versions up to 3.3.12
Description:
The issue allows attackers to shop for free in merchants' websites and mobile apps by generating a crafted authentication code (MAC) based on a secret key which is NULL. This is due to an improper verification of cryptographic signature.
Recommendations:
For Union Pay versions up to 3.3.12, update to a version that properly verifies cryptographic signatures to prevent exploitation. As a temporary workaround, consider implementing additional validation checks for authentication codes to minimize the risk of exploitation.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Union Pay