Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6522-r5wp-vr5j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

nvd
больше 10 лет назад

The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

fstec
больше 10 лет назад

Уязвимость операционной системы iOS, позволяющая нарушителю проводить атаки типа "человек посередине"

EPSS

Процентиль: 48%
0.0025
Низкий