Cryptographic issues in macOS and macOS Server - CVE-2011-3444

 

Cryptographic issues in macOS and macOS Server - CVE-2011-3444

Published: February 2, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44329
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-3444
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Apple Inc.
Affected software:
macOS
macOS Server

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.


How to mitigate CVE-2011-3444

Install update from vendor's website.

Sources