CVE-2018-4111Improper Verification of Cryptographic Signature in Apple MAC OS X

Severity
5.9MEDIUMNVD
EPSS
0.4%
top 36.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 13

Description

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid S/MIME signature.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

🔴Vulnerability Details

1
GHSA
GHSA-x4qp-x57c-wv5h: An issue was discovered in certain Apple products2022-05-13

📋Vendor Advisories

1
Apple
CVE-2018-4111: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan2018-03-29