Meafinancial operates a line of mobile banking applications deployed across regional and community financial institutions, including platforms such as AVB Bank Mobile Banking, Blue Ridge Bank and Trust's mobile offering, and CB2Go. The vendor's vulnerability profile centers on a singular, recurring weakness class: improper certificate validation in these client-side banking applications, which affects the security of data in transit and the integrity of server authentication for financial transactions. This focused exposure pattern reflects the cryptographic and TLS-handling demands of applications that must authenticate and encrypt communications with banking infrastructure. Defenders should prioritize patches for these mobile applications in financial environments and monitor for certificate-validation issues across the vendor's portfolio; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meafinancial over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9600MEDIUM The "Peoples Bank Tulsa" by Peoples Bank - OK app 3.0.2 -- aka peoples-bank-tulsa/id1074279285 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the- | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9598MEDIUM The "Morton Credit Union Mobile Banking" by Morton Credit Union app 3.0.1 -- aka morton-credit-union-mobile-banking/id1119623070 for iOS does not verify X.509 certificates from SSL | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9597MEDIUM The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and-trust-co-mobile-banking/id699679197 for iOS does not verify | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9596MEDIUM The "CFB Mobile Banking" by Citizens First Bank Wisconsin app 3.0.1 -- aka cfb-mobile-banking/id1081102805 for iOS does not verify X.509 certificates from SSL servers, which allows | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9594MEDIUM The "SVB Mobile" by Sauk Valley Bank Mobile Banking app 3.0.0 -- aka svb-mobile/id796429885 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mid | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9593MEDIUM The "Oculina Mobile Banking" by Oculina Bank app 3.0.0 -- aka oculina-mobile-banking/id867025690 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-th | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9592MEDIUM The "Your Legacy Federal Credit Union Mobile Banking" by Your Legacy Federal Credit Union app 3.0.1 -- aka your-legacy-federal-credit-union-mobile-banking/id919131389 for iOS does | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9589MEDIUM The "SCSB Shelbyville IL Mobile Banking" by Shelby County State Bank app 3.0.0 -- aka scsb-shelbyville-il-mobile-banking/id938960224 for iOS does not verify X.509 certificates from | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9588MEDIUM The "Oritani Mobile Banking" by Oritani Bank app 3.0.0 -- aka oritani-mobile-banking/id778851066 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-th | Jun 16, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-9587MEDIUM The "PCSB BANK Mobile" by PCSB Bank app 3.0.4 -- aka pcsb-bank-mobile/id1067472090 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac | Jun 16, 2017 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meafinancial.
Media articles that mention a CVE ID that affects a product developed by Meafinancial — matched by CVE ID, not by vendor name.