CVE-2015-5894Apple MAC OS X vulnerability

CWE-173 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9
Latest updateMay 17

Description

The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-77w5-p2v7-hh9q: The X2022-05-17

📋Vendor Advisories

1
Apple
CVE-2015-5894: OS X El Capitan v10.11