VulnerabilityModified
CVE-2015-1129
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.
MEDIUM 4.3EPSS 0.96%
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- apple/iphone os · apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlVendor Advisory
- http://www.securitytracker.com/id/1032047
- https://support.apple.com/HT204658Vendor Advisory
- https://support.apple.com/HT205212Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlVendor Advisory
- http://www.securitytracker.com/id/1032047
- https://support.apple.com/HT204658Vendor Advisory
- https://support.apple.com/HT205212Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.