CVE-2010-1800Sensitive Information Exposure in Apple MAC OS X

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 46.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 17

Description

CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x10.6.3, 10.6.4+1
NVDapple/mac_os_x_server10.6.3, 10.6.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wmgm-8v4f-275p: CFNetwork in Apple Mac OS X 102022-05-17
CVEList
CVE-2010-1800: CFNetwork in Apple Mac OS X 102010-08-25
CVE-2010-1800 — Sensitive Information Exposure in Apple | cvebase