CVE-2020-5523: 77bank 77 Bank

High severity, CVSS 7.4. EPSS: 1.2% chance of exploitation in the next 30 days.

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

  • 77bank 77 Bank: up to and including 2.0.1
  • Ashikagabank Ashigin: up to and including 1.0.4
  • Hokkaidobank Dogin: up to and including 3.0.1
  • Hokugin Hokuriku Bank Portal: up to and including 2.0.1
  • Naganobank Nagagin: up to and including 1.0.1
  • Nttdata Mypallete: affected versions not specified
  • Shikokubank Shikoku Bank: up to and including 2.0.1
  • Sihd-Bk Ikeda Senshu Bank: up to and including 3.0.4
  • Tohoku-Bank Tougin: up to and including 1.0.1

Published 2020-01-28. Last modified 2026-06-17.