PT-2021-05: Lack of Amount/CVMResults fields checking for Public Transport Schemes
Visa Tokenisation Service (VTS), MasterCard Tokenisation Service (MDES)
Severity level: Medium
Lack of Amount/CVMResults fields checking for Public Transport Schemes
Access Vector: Local
Base Score: 4.1
Mobile wallets allow to charge one amount within the Public Transport Scheme' cryptogram and charge a different amount using any payment terminal in the end. This is due to EMV standards and is a requirement for modern payments when the price shown on the terminal is different from the actual amount that's being charged.
Mobile wallet passes the information about the type of cardholder verification (whether it was made on the locked phone or a fingerprint/PIN were presented, and the cardholder unlocked the phone). Along with the Amount and MCC, the tokenisation service could appropriately decide to reject or approve transactions.
October, 2021 - Vendor notification date