VulnerabilityModified
CVE-2017-2385
It allows local users to obtain access to locked keychain items via unspecified vectors.
MEDIUM 5.5EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://www.securityfocus.com/bid/97136Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038137
- https://support.apple.com/HT207600Vendor Advisory
- http://www.securityfocus.com/bid/97136Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038137
- https://support.apple.com/HT207600Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.