Proxy Authentication Issue in Apple iOS, tvOS, and OS X Products
CVE-2016-4642

5.9MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
11 January 2019

Summary

In specific versions of Apple's iOS, tvOS, and OS X El Capitan, a vulnerability existed where the proxy authentication mechanism incorrectly indicated that credentials were securely transmitted to HTTP proxies. This security flaw could potentially lead to unauthorized access and compromise user data by misrepresenting the security of credential transmission. Apple addressed this issue in subsequent updates by implementing improved notifications to make users aware of the potential risks associated with proxy authentication.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.