VulnerabilityModified
CVE-2018-4397
Analytics data was sent using HTTP rather than HTTPS.
MEDIUM 4.3EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/apple support
- Source
- product-security@apple.com
References
- https://support.apple.com/kb/HT209117Vendor Advisory
- https://support.apple.com/kb/HT209117Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.