VulnerabilityModified
CVE-2021-30997
An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.
HIGH 7.5EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- apple/ipados · apple/iphone os
- Source
- product-security@apple.com
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.