CVE-2015-1147Sensitive Information Exposure in Apple MAC OS X

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 36.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 14

Description

Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-vr22-wfqg-j5gh: Open Directory Client in Apple OS X before 102022-05-14

📋Vendor Advisories

1
Apple
CVE-2015-1147: OS X Yosemite v10.10.3 and Security Update 2015-004