Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhj2-pggv-wgpc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.

The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 12 лет назад

The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-20