PT-2021-05: Lack of Amount/CVMResults fields checking for Public Transport Schemes Visa Tokenisation Service (VTS), MasterCard Tokenisation Service (MDES)Severity:Severity level: Medium Lack of Amount/CVMResults fields checking for Public Transport Schemes Access Vector: LocalCVSS v3.0 Base Score: 4.1 Vector: (AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N) Vulnerability description:Mobile wallets allow to charge one amount within the Public Transport Scheme' cryptogram and charge a different amount using any payment terminal in the end. This is due to EMV standards and is a requirement for modern payments when the price shown on the terminal is different from the actual amount that's being charged. Mobile wallet passes the information about the type of cardholder verification (whether it was made on the locked phone or a fingerprint/PIN were presented, and the cardholder unlocked the phone). Along with the Amount and MCC, the tokenisation service could appropriately decide to reject or approve transactions.Advisory status:October, 2021 - Vendor notification dateCredits:Timur Yunusov