CVE-2016-4644
published 2019-01-11CVE-2016-4644: In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication…
PriorityP335medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.33%
67.8th percentile
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | < 9.2.2 | 9.2.2 |
| apple | ios | — | — |
| apple | iphone_os | < 9.3.3 | 9.3.3 |
| apple | mac_os | >= 10.11.0 < 10.11.6 | 10.11.6 |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| apple | tvos | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4644: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4644 [MEDIUM] CVE-2016-4644: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4644
Component: CFNetwork Credentials
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Apple
CVE-2016-4644: tvOS 9.2.2
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4644 [MEDIUM] CVE-2016-4644: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4644
Component: CFNetwork Credentials
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Apple
CVE-2016-4644: iOS 9.3.3
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4644 [MEDIUM] CVE-2016-4644: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4644
Component: CFNetwork Credentials
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
GHSA
GHSA-p9wg-r6p8-r2pv: In iOS before 9
ghsa_unreviewed·2022-05-14
CVE-2016-4644 [MEDIUM] CWE-200 GHSA-p9wg-r6p8-r2pv: In iOS before 9
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-11
Published