VYPR
Vendor

National Payments Corporation Of India

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2017-9821CriAug 24, 2018
    risk 0.64cvss 9.8epss 0.01

    The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.

  • CVE-2017-9820CriAug 24, 2018
    risk 0.64cvss 9.8epss 0.02

    The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.

  • CVE-2017-9819CriAug 24, 2018
    risk 0.64cvss 9.8epss 0.02

    The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.

  • CVE-2017-9818HigAug 24, 2018
    risk 0.49cvss 7.5epss 0.01

    The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.