| Vulnerability Name: | CVE-2018-4293 (CCN-146579) | ||||||||||||
| Assigned: | 2018-07-09 | ||||||||||||
| Published: | 2018-07-09 | ||||||||||||
| Updated: | 2019-04-05 | ||||||||||||
| Summary: | A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-4293 Source: XF Type: UNKNOWN apple-macos-cve20184293-sec-bypass(146579) Source: CCN Type: Apple security document HT208935 About the security content of watchOS 4.3.2 Source: CCN Type: Apple security document HT208937 About the security content of macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208932 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208933 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208935 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208936 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208937 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT208938 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||