CVE Vulnerabilities

CVE-2018-4086

Improper Certificate Validation

Published: Apr 03, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the Security component. It allows remote attackers to spoof certificate validation via crafted name constraints.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Apple_tvApple*11.2.5 (excluding)
Iphone_osApple*11.2.5 (excluding)
Mac_os_xApple*10.13.3 (excluding)
WatchosApple*4.2.2 (excluding)

Potential Mitigations

References