VulnerabilityModified
CVE-2018-4321
A validation issue existed in the entitlement verification.
MEDIUM 5.3EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/iphone os · apple/mac os x · apple/tvos
- Source
- product-security@apple.com
References
- https://support.apple.com/kb/HT209106Vendor Advisory
- https://support.apple.com/kb/HT209107Vendor Advisory
- https://support.apple.com/kb/HT209139Vendor Advisory
- https://support.apple.com/kb/HT209106Vendor Advisory
- https://support.apple.com/kb/HT209107Vendor Advisory
- https://support.apple.com/kb/HT209139Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.