PT-2021-05: Lack of Amount/CVMResults fields checking for Public Transport Schemes

Visa Tokenisation Service (VTS), MasterCard Tokenisation Service (MDES)

Severity:

Severity level: Medium
Lack of Amount/CVMResults fields checking for Public Transport Schemes
Access Vector: Local

CVSS v3.0
Base Score: 4.1
Vector: (AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N)

Vulnerability description:

Mobile wallets allow to charge one amount within the Public Transport Scheme' cryptogram and charge a different amount using any payment terminal in the end. This is due to EMV standards and is a requirement for modern payments when the price shown on the terminal is different from the actual amount that's being charged.
Mobile wallet passes the information about the type of cardholder verification (whether it was made on the locked phone or a fingerprint/PIN were presented, and the cardholder unlocked the phone). Along with the Amount and MCC, the tokenisation service could appropriately decide to reject or approve transactions.

Advisory status:

October, 2021 - Vendor notification date

Credits:

Timur Yunusov

Threatscape