Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Conclusion & alert: CVE-2020-5523 is rated Moderate Risk (50.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.45%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.50% | 0.45% | -0.05% |
| 2 | 2025-03-29 | 0.45% | 0.50% | +0.05% |
| 3 | 2025-03-17 | — | 0.45% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.4 | 3.1 | HIGH |
|
2.2 | 5.2 | [email protected] |
| 5.8 | 2.0 | MEDIUM |
|
8.6 | 4.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| 77bank | 77_bank | <= 2.0.1 | cpe:2.3:a:77bank:77_bank:*:*:*:*:*:android:*:* |
| ashikagabank | ashigin | <= 1.0.4 | cpe:2.3:a:ashikagabank:ashigin:*:*:*:*:*:android:*:* |
| hokkaidobank | dogin | <= 3.0.1 | cpe:2.3:a:hokkaidobank:dogin:*:*:*:*:*:android:*:* |
| hokugin | hokuriku_bank_portal | <= 2.0.1 | cpe:2.3:a:hokugin:hokuriku_bank_portal:*:*:*:*:*:android:*:* |
| naganobank | nagagin | <= 1.0.1 | cpe:2.3:a:naganobank:nagagin:*:*:*:*:*:android:*:* |
| nttdata | mypallete | — | cpe:2.3:a:nttdata:mypallete:-:*:*:*:*:android:*:* |
| shikokubank | shikoku_bank | <= 2.0.1 | cpe:2.3:a:shikokubank:shikoku_bank:*:*:*:*:*:android:*:* |
| sihd-bk | ikeda_senshu_bank | <= 3.0.4 | cpe:2.3:a:sihd-bk:ikeda_senshu_bank:*:*:*:*:*:android:*:* |
| tohoku-bank | tougin | <= 1.0.1 | cpe:2.3:a:tohoku-bank:tougin:*:*:*:*:*:android:*:* |
| URL | Tags |
|---|---|
| http://jvn.jp/en/jp/JVN28845872/index.html | Third Party Advisory |
| http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html | Third Party Advisory |
| https://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf | Third Party Advisory |
| https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf | Third Party Advisory |
| https://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf | Third Party Advisory |
| https://www.hokugin.co.jp/info/archives/personal/2020/1913.html | Third Party Advisory |
| https://www.naganobank.co.jp/soshiki/2/app-ssl.html | Third Party Advisory |
| https://www.shikokubank.co.jp/info/apps20200128.html | Third Party Advisory |
| https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf | Third Party Advisory |
| https://www.tohoku-bank.co.jp/news/topics/200128_applissl.html | Third Party Advisory |