NPCI operates India's primary digital payments infrastructure, with its BHIM mobile application serving as a widely deployed entry point for financial transactions across the subcontinent. Its disclosed vulnerabilities center on authentication and credential-management weaknesses—including improper authentication, hard-coded credentials, and weak password requirements—that reflect the authentication-layer demands of a financial application handling sensitive user account access.
The number and severity of CVEs published that impact products developed by Npci over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9821CRITICAL The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes | Aug 24, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-9820CRITICAL The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes | Aug 24, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-9819CRITICAL The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authent | Aug 24, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-9818HIGH The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access. | Aug 24, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Npci.
Media articles that mention a CVE ID that affects a product developed by Npci — matched by CVE ID, not by vendor name.