CVE-2018-4321Improper Input Validation in Apple Tvos

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 48.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 14

Description

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

Appleapple/macos_mojave10.14
NVDapple/tvos< 12
NVDapple/mac_os_x< 10.14
Appleapple/tvos12
NVDapple/iphone_os< 12.0

🔴Vulnerability Details

1
GHSA
GHSA-2cp8-mv48-5393: A validation issue existed in the entitlement verification2022-05-14

📋Vendor Advisories

3
Apple
CVE-2018-4321: macOS Mojave 10.142018-09-24
Apple
CVE-2018-4321: tvOS 122018-09-17
Apple
CVE-2018-4321: iOS 122018-09-17