VulnerabilityModified
CVE-2021-1815
A parsing issue in the handling of directory paths was addressed with improved path validation.
MEDIUM 5.5EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT212317Vendor Advisory
- https://support.apple.com/en-us/HT212323Vendor Advisory
- https://support.apple.com/en-us/HT212324Vendor Advisory
- https://support.apple.com/en-us/HT212325Vendor Advisory
- https://support.apple.com/en-us/HT212317Vendor Advisory
- https://support.apple.com/en-us/HT212323Vendor Advisory
- https://support.apple.com/en-us/HT212324Vendor Advisory
- https://support.apple.com/en-us/HT212325Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.