SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-4397

Analytics data was sent using HTTP rather than HTTPS.

MEDIUM 4.3EPSS 0.82%

Does this matter?

Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.

Description

Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.82% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
apple/apple support
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.