USAA appreciates and supports engagement with security community when potential security vulnerabilities in our digital assets are reported to us in accordance with Responsible Disclosure policy.
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | USAA Mobile Application for Android |
api | https://api.usaa.com/ |
api | https://mapi.usaa.com/ |
api | https://wsmbr.usaa.com/ |
api | https://api2.usaa.com/ |
api | https://b2bapi.usaa.com |
api | https://b2blsapi.usaa.com |
api | https://service2.usaa.com |
api | https://ws.usaa.com |
api | mcontentapi.usaa.com |
api | contentapi.usaa.com |
api | api-life.usaa.com |
ios_application | USAA Mobile Application for iOS |
web_application | mobile.usaa.com |
web_application | partners.usaa.com |
web_application | www.usaa.com |
web_application | https://content.usaa.com |
web_application | https://l.usaa.com/ |
web_application | https://login.usaa.com/ |
web_application | https://mobileapps.usaa.com/ |
web_application | https://my.usaa.com/ |
web_application | https://s.usaa.com/ |
web_application | https://guest.usaa.com/ |
web_application | https://mguest.usaa.com/ |
web_application | https://nvoice.usaa.com/ |
web_application | https://www.usaainsurance.com/ |
web_application | https://liveassist.usaa.com/ |
web_application | https://liveassist11.usaa.com/ |
web_application | https://liveassist12.usaa.com/ |
web_application | https://liveassist21.usaa.com/ |
web_application | https://liveassist22.usaa.com/ |
web_application | empauthn.usaa.com |
web_application | mam-prod-dfw.usaa.com |
web_application | mdm1.usaa.com |
web_application | mydesktop.usaa.com |
web_application | myvpn.usaa.com |
web_application | webmail.usaa.com |
web_application | utv.usaa.com |
web_application | externalconnect.usaa.com |
web_application | mam-prod-itc.usaa.com |
web_application | mam-vpn-itc.usaa.com |
web_application | https://nicewfm.usaa.com |
web_application | https://vlagg.usaa.com |
web_application | https://vlapi.usaa.com |
web_application | https://vendorss.usaa.com |
web_application | ww2.usaa.com |
web_application | vanityocp.usaa.com |
web_application | utvqa.usaa.com |
web_application | static.usaa.com |
web_application | mstatic.usaa.com |
web_application | external.connect.usaa.com |
web_application | https://authn.usaa.com/ |
This program crawled on the 2018-09-06 is sorted as bounty.
FireBounty © 2015-2024