SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-13909

A local attacker may gain access to iCloud authentication tokens.

MEDIUM 5.5EPSS 0.23%

Does this matter?

Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.

Description

An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.23% probability · 14th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
apple/mac os x
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.