Vulnerability Name:
CVE-2021-30738 (CCN-202414)
Assigned:
2021-05-24
Published:
2021-05-24
Updated:
2021-09-22
Summary:
A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Mojave. An issue with path validation logic for hardlinks was addressed with improved path sanitization.
CVSS v3 Severity:
5.5 Medium
(CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
)
4.8 Medium
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
High
Availibility (A):
None
6.2 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
)
5.4 Medium
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
High
Availibility (A):
None
CVSS v2 Severity:
2.1 Low
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Partial
Availibility (A):
None
4.9 Medium
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:N/C:N/I:C/A:N
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Complete
Availibility (A):
None
Vulnerability Type:
CWE-noinfo
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2021-30738
Source: XF
Type: UNKNOWN
apple-macos-cve202130738-file-overwrite(202414)
Source: CCN
Type: Apple security document HT212529
About the security content of macOS Big Sur 11.4
Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT212529
Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT212531
Vulnerable Configuration:
Configuration 1
:
cpe:/o:apple:macos:*:*:*:*:*:*:*:*
(Version >= 11.0.1 and < 11.4)
OR
cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:*
(Version >= 10.14.0 and <= 10.14.5)
OR
cpe:/o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-004:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-005:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-006:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-007:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2021-001:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2021-002:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:security_update_2021-003:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:supplemental_update:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.14.6:supplemental_update_2:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:apple:macos_big_sur:11.3:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
apple
macos *
apple
mac os x *
apple
mac os x 10.14.6 -
apple
mac os x 10.14.6 security_update_2019-001
apple
mac os x 10.14.6 security_update_2019-002
apple
mac os x 10.14.6 security_update_2019-004
apple
mac os x 10.14.6 security_update_2019-005
apple
mac os x 10.14.6 security_update_2019-006
apple
mac os x 10.14.6 security_update_2019-007
apple
mac os x 10.14.6 security_update_2020-001
apple
mac os x 10.14.6 security_update_2020-002
apple
mac os x 10.14.6 security_update_2020-003
apple
mac os x 10.14.6 security_update_2020-004
apple
mac os x 10.14.6 security_update_2020-005
apple
mac os x 10.14.6 security_update_2020-006
apple
mac os x 10.14.6 security_update_2020-007
apple
mac os x 10.14.6 security_update_2021-001
apple
mac os x 10.14.6 security_update_2021-002
apple
mac os x 10.14.6 security_update_2021-003
apple
mac os x 10.14.6 supplemental_update
apple
mac os x 10.14.6 supplemental_update_2
apple
macos big sur 11.3