Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f5j7-q9w6-v358

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.

The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.

EPSS

Процентиль: 21%
0.00069
Низкий

Связанные уязвимости

nvd
больше 10 лет назад

The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.

fstec
больше 10 лет назад

Уязвимость операционной системы Mac OS X, позволяющая нарушителю модифицировать микропрограммное обеспечение

EPSS

Процентиль: 21%
0.00069
Низкий