CVE CVE-2018-16179 Mappings

The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
CVE-2018-16179 Mizuho Direct App for Android uncategorized T1557 Man-in-the-Middle
CVE-2018-16179 Mizuho Direct App for Android uncategorized T1211 Exploitation for Defense Evasion