CVE Database · CVE-2014-7589
CVSS v3.1
N/A
EPSS
0.27%
Published
Oct 20, 2014
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Industrial and Commercial Bank of China (ICBC) Banking (aka com.icbc.android) application 2.40 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Weaknesses (CWE)
Affected Products (1)
References (6)