| Vulnerability Name: | CVE-2014-4425 (CCN-97640) | ||||||||
| Assigned: | 2014-10-16 | ||||||||
| Published: | 2014-10-16 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver begins" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: APPLE Type: UNKNOWN APPLE-SA-2014-10-16-1 Source: MITRE Type: CNA CVE-2014-4425 Source: CCN Type: Apple Web Site About the security content of OS X Yosemite v10.10 Source: BID Type: UNKNOWN 70630 Source: CCN Type: BID-70630 Apple Mac OS X CVE-2014-4425 Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1031063 Source: XF Type: UNKNOWN macosx-cve20144425-sec-bypass(97640) Source: XF Type: UNKNOWN macosx-cve20144425-sec-bypass(97640) Source: CONFIRM Type: Vendor Advisory https://support.apple.com/kb/HT6535 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||