CVE Vulnerabilities

CVE-2017-6988

Improper Certificate Validation

Published: May 22, 2017 | Modified: Jul 08, 2017
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the 802.1X component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication, because EAP-TLS certificate validation mishandles certificate changes.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple * 10.12.4 (including)

Potential Mitigations

References