TROYANOSYVIRUS
Back to CVEs

CVE-2017-13909

MEDIUM
5.5

Description

An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

CVE Details

CVSS v3.1 Score5.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published12/23/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

apple:mac_os_x

Weaknesses (CWE)

CWE-922

References

https://support.apple.com/en-us/HT208144(product-security@apple.com)
https://support.apple.com/en-us/HT208144(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.