VulnerabilityModified
CVE-2011-3212
CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk…
LOW 2.1EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- apple/mac os x · apple/mac os x server
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://osvdb.org/76362
- http://support.apple.com/kb/HT5002Vendor Advisory
- http://support.apple.com/kb/HT5281
- http://www.securityfocus.com/bid/50085
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://osvdb.org/76362
- http://support.apple.com/kb/HT5002Vendor Advisory
- http://support.apple.com/kb/HT5281
- http://www.securityfocus.com/bid/50085
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.