ITM MacOS Agent Improper Certificate Validation
CVE-2023-4801
7.5HIGH
Summary
An improper certification validation vulnerability exists in the Insider Threat Management (ITM) Agent designed for MacOS. This flaw could potentially enable an unauthenticated attacker within the same network vicinity to execute a man-in-the-middle attack, thereby intercepting communications between the agent and the ITM server after the agent's registration. All versions earlier than 7.14.3.69 are vulnerable, while agents running on Windows, Linux, or Cloud environments are not impacted.
Affected Version(s)
Insider Threat Management MacOS 0 <= 7.14.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved