Описание
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.12.3 (включая)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00081
Низкий
6.8 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-310
Связанные уязвимости
CVSS3: 6.8
github
больше 3 лет назад
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.
EPSS
Процентиль: 24%
0.00081
Низкий
6.8 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-310