CVE Vulnerabilities

CVE-2018-4086

Improper Certificate Validation

Published: Apr 03, 2018 | Modified: May 04, 2018
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the Security component. It allows remote attackers to spoof certificate validation via crafted name constraints.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Apple_tv Apple * 11.2.5 (excluding)
Iphone_os Apple * 11.2.5 (excluding)
Mac_os_x Apple * 10.13.3 (excluding)
Watchos Apple * 4.2.2 (excluding)

Potential Mitigations

References