CVE-2018-4100
published 2018-04-03CVE-2018-4100: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.92%
85.6th percentile
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 11.2.5 | 11.2.5 |
| apple | mac_os_x | < 10.13.3 | 10.13.3 |
| apple | macos_high_sierra_10.13.3_security_update_2018-001_sierra_and_security_update_20 | — | — |
| apple | watchos | < 4.2.2 | 4.2.2 |
| apple | watchos | — | — |
| citrix | netscaler_adc_gateway | — | — |
| citrix | sd-wan | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
vendor_cisco·2018-06-20·CVSS 7.2
CVE-2018-0300 [HIGH] CWE-22 Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
A vulnerability in the process of uploading new application images to the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker using path traversal techniques to create or overwrite arbitrary files on an affected device.
The vulnerability is due to insufficient validation during the application image upload process. An attacker could exploit this vulnerability by creating an application image containing malicious code and installing the image on the affected device using the CLI or web-based user interface (web UI). These actions occur prior to signature verification and could allo
Apple
CVE-2018-4100: iOS 11.4
vendor_apple·2018-05-29·CVSS 7.5
CVE-2018-4100 [HIGH] CVE-2018-4100: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4100
Component: Contacts
Impact: Processing a maliciously crafted vcf file may lead to a denial of service
Description: A validation issue existed in the handling of phone numbers. This issue was addressed with improved validation of phone numbers.
Citrix
CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build
vendor_citrix·2018-03-01·CVSS 7.5
CVE-2018-5314 [HIGH] CWE-287 CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build
CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Apple
CVE-2018-4100: watchOS 4.2.2
vendor_apple·2018-01-23·CVSS 7.5
CVE-2018-4100 [HIGH] CVE-2018-4100: watchOS 4.2.2
Apple Security Update: About the security content of watchOS 4.2.2
Product: watchOS
Version: 4.2.2
CVE: CVE-2018-4100
Component: LinkPresentation
Impact: Processing a maliciously crafted text message may lead to application denial of service
Description: A resource exhaustion issue was addressed with improved input validation.
Apple
CVE-2018-4100: iOS 11.2.5
vendor_apple·2018-01-23·CVSS 7.5
CVE-2018-4100 [HIGH] CVE-2018-4100: iOS 11.2.5
Apple Security Update: About the security content of iOS 11.2.5
Product: iOS
Version: 11.2.5
CVE: CVE-2018-4100
Component: LinkPresentation
Impact: Processing a maliciously crafted text message may lead to application denial of service
Description: A resource exhaustion issue was addressed with improved input validation.
Apple
CVE-2018-4100: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
vendor_apple·2018-01-23·CVSS 7.5
CVE-2018-4100 [HIGH] CVE-2018-4100: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
Product: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
CVE: CVE-2018-4100
Component: LinkPresentation
Impact: Processing a maliciously crafted text message may lead to application denial of service
Description: A resource exhaustion issue was addressed with improved input validation.
Cisco
Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0300 Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
CVE-2018-0300: Cisco Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance Path Traversal Vulnerability
A vulnerability in the process of uploading new application images to the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker using path traversal techniques to create or overwrite arbitrary files on an affected device. The vulnerability is due to insufficient validation during the application image upload process. An attacker could exploit this vulnerability by creating an application image containing malicious code and installing the image on the affected device using the CLI or web-based user interface (web UI). These actions occur prior to signature verification
GHSA
GHSA-jvg8-88xj-vprr: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-13
CVE-2018-4100 [HIGH] CWE-400 GHSA-jvg8-88xj-vprr: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102772http://www.securitytracker.com/id/1040265http://www.securitytracker.com/id/1040267https://support.apple.com/HT208463https://support.apple.com/HT208464https://support.apple.com/HT208465http://www.securityfocus.com/bid/102772http://www.securitytracker.com/id/1040265http://www.securitytracker.com/id/1040267https://support.apple.com/HT208463https://support.apple.com/HT208464https://support.apple.com/HT208465
2018-04-03
Published