CVE-2018-4397
published 2019-04-03CVE-2018-4397: Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple…
PriorityP419medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.83%
53.4th percentile
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_support | < 2.4 | 2.4 |
| apple | apple_support_2.4_for_ios | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g665-9726-cg3r: Analytics data was sent using HTTP rather than HTTPS
ghsa_unreviewed·2022-05-14
CVE-2018-4397 [MEDIUM] CWE-20 GHSA-g665-9726-cg3r: Analytics data was sent using HTTP rather than HTTPS
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
Apple
CVE-2018-4397: Apple Support 2.4 for iOS
vendor_apple·2018-09-17·CVSS 4.3
CVE-2018-4397 [MEDIUM] CVE-2018-4397: Apple Support 2.4 for iOS
Apple Security Update: About the security content of Apple Support 2.4 for iOS
Product: Apple Support 2.4 for iOS
CVE: CVE-2018-4397
Component: Analytics
Impact: An attacker in a privileged network position may be able to intercept analytics data sent to Apple
Description: Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS.
Citrix
Citrix Security Bulletin CTX238022
vendor_citrix·CVSS 3.1
CVE-2018-16968 [LOW] Citrix Security Bulletin CTX238022
Citrix Security Bulletin CTX238022
CVE References: CVE-2018-16968, CVE-2018-16969, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX234679
vendor_citrix·CVSS 7.8
CVE-2018-8897 [HIGH] Citrix Security Bulletin CTX234679
Citrix Security Bulletin CTX234679
CVE References: CVE-2018-8897, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX239432
vendor_citrix·CVSS 7.8
CVE-2018-19961 [HIGH] Citrix Security Bulletin CTX239432
Citrix Security Bulletin CTX239432
CVE References: CVE-2018-19961, CVE-2018-19962, CVE-2018-19965, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX247736
vendor_citrix·CVSS 9.1
CVE-2018-18571 [CRITICAL] Citrix Security Bulletin CTX247736
Citrix Security Bulletin CTX247736
CVE References: CVE-2018-18571, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX232199
vendor_citrix·CVSS 7.5
CVE-2018-5314 [HIGH] Citrix Security Bulletin CTX232199
Citrix Security Bulletin CTX232199
CVE References: CVE-2018-5314, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX234869
vendor_citrix·CVSS 9.8
CVE-2018-7218 [CRITICAL] Citrix Security Bulletin CTX234869
Citrix Security Bulletin CTX234869
CVE References: CVE-2018-7218, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX236548
vendor_citrix·CVSS 9.8
CVE-2018-14007 [CRITICAL] Citrix Security Bulletin CTX236548
Citrix Security Bulletin CTX236548
CVE References: CVE-2018-14007, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX235745
vendor_citrix·CVSS 5.6
CVE-2018-3665 [MEDIUM] Citrix Security Bulletin CTX235745
Citrix Security Bulletin CTX235745
CVE References: CVE-2018-3665, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX239002
vendor_citrix·CVSS 4.8
CVE-2018-18517 [MEDIUM] Citrix Security Bulletin CTX239002
Citrix Security Bulletin CTX239002
CVE References: CVE-2018-18517, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX232161
vendor_citrix·CVSS 8.8
CVE-2018-6186 [HIGH] Citrix Security Bulletin CTX232161
Citrix Security Bulletin CTX232161
CVE References: CVE-2018-6186, CVE-2018-6808, CVE-2018-6809, CVE-2018-6810, CVE-2018-6811, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX234879
vendor_citrix·CVSS 9.8
CVE-2018-10648 [CRITICAL] Citrix Security Bulletin CTX234879
Citrix Security Bulletin CTX234879
CVE References: CVE-2018-10648, CVE-2018-10649, CVE-2018-10650, CVE-2018-10651, CVE-2018-10652, CVE-2018-10653, CVE-2018-10654, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-03
Published