Man-in-the-middle attack in macOS - CVE-2018-4221

 

Man-in-the-middle attack in macOS - CVE-2018-4221

Published: June 4, 2018


Vulnerability identifier: #VU13172
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4221
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.

The vulnerability exists due to a flaw in the Security component in the handling of S-MIME client certificates. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the affected app and track the target user.


Affected software

macOS
Apple iOS
IBM Watson Explorer Deep Analytics Edition Analytical Components

How to mitigate CVE-2018-4221

Update to version 10.13.4.

IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.16

External References

Related Security Bulletins