Vulnerabilities > Npci

DATE CVE VULNERABILITY TITLE RISK
2018-08-24 CVE-2017-9821 Use of Hard-coded Credentials vulnerability in Npci Bharat Interface for Money (Bhim) 1.3
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.
network
low complexity
npci CWE-798
critical
9.8
2018-08-24 CVE-2017-9820 Improper Authentication vulnerability in Npci Bharat Interface for Money (Bhim) 1.3
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.
network
low complexity
npci CWE-287
critical
9.8
2018-08-24 CVE-2017-9819 Improper Authentication vulnerability in Npci Bharat Interface for Money (Bhim) 1.3
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.
network
low complexity
npci CWE-287
critical
9.8
2018-08-24 CVE-2017-9818 Weak Password Requirements vulnerability in Npci Bharat Interface for Money (Bhim) 1.3
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
network
low complexity
npci CWE-521
7.5