The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Sep 16, 2013 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Aug 28, 2015 | Sep 16, 2013 |
| Apple Osx Ipsec | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Sep 17, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub