PT-2021-5136 · Mastercard+1 · Mastercard Tokenisation Service+1

Published

2021-03-01

·

Updated

2021-03-01

CVSS v2.0

3.8

Low

VectorAV:L/AC:H/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions MasterCard Tokenisation Service (MDES) (affected versions not specified) Visa Tokenisation Service (VTS) (affected versions not specified)
Description The issue is related to the arbitrary modification of the Amount field in the ISO 8583 Authorisation Request package. This could allow an attacker to use cryptograms to make fraudulent payments.
Recommendations For MasterCard Tokenisation Service (MDES), at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Visa Tokenisation Service (VTS), at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05930

Affected Products

Mastercard Tokenisation Service
Visa Tokenisation Service