Field Assessment
AI analysis pending.
CVE
CVE-2017-9599
Severity
MEDIUM
CVSS
5.9
EPSS
0.50%
Original Filing — NVD Description
The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id891343006 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.