Vulnerability Name: | CVE-2017-7150 (CCN-133022) | ||||||||||||
Assigned: | 2017-10-05 | ||||||||||||
Published: | 2017-10-05 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-521 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-7150 Source: BID Type: Third Party Advisory, VDB Entry 101177 Source: CCN Type: BID-101177 Apple macOS CVE-2017-7150 Security Bypass Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039430 Source: XF Type: UNKNOWN apple-macos-cve20177150-sec-bypass(133022) Source: CCN Type: Apple security document HT208165 About the security content of macOS High Sierra 10.13 Supplemental Update Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT208165 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |