Vulnerability Name: | CVE-2011-3462 (CCN-72901) | ||||||||
Assigned: | 2011-09-13 | ||||||||
Published: | 2012-02-01 | ||||||||
Updated: | 2012-02-03 | ||||||||
Summary: | Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-3462 Source: APPLE Type: Vendor Advisory APPLE-SA-2012-02-01-1 Source: CCN Type: SA47843 Apple Mac OS X Multiple Vulnerabilities Source: CCN Type: Apple Web site About the security content of OS X Lion v10.7.3 and Security Update 2012-001 Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT5130 Source: CCN Type: BID-51818 Apple Mac OS X CVE-2011-3462 Security Bypass Vulnerability Source: XF Type: UNKNOWN osx-timemachine-info-disclosure(72901) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |