ID

VAR-201705-3992


CVE

CVE-2017-6988


TITLE

Apple macOS of 802.1X Vulnerability in obtaining network credentials of arbitrary user in component

Trust: 0.8

sources: JVNDB: JVNDB-2017-003849

DESCRIPTION

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication, because EAP-TLS certificate validation mishandles certificate changes. Apple macOS is prone to multiple security vulnerabilities. An attacker can exploit these issues to gain elevated privileges, perform unauthorized actions and execute arbitrary code with kernel privileges. Failed exploit attempts will likely cause a denial-of-service condition. Apple macOS Sierra is a dedicated operating system developed by Apple for Mac computers. 802.1X is one of the client or server-based access control and authentication protocol components. The vulnerability stems from the fact that EAP-TLS certificate verification does not properly handle certificate replacement

Trust: 1.98

sources: NVD: CVE-2017-6988 // JVNDB: JVNDB-2017-003849 // BID: 98483 // VULHUB: VHN-115191

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.12.4

Trust: 1.4

vendor:applemodel:mac os xscope:lteversion:10.12.4

Trust: 1.0

vendor:applemodel:macosscope:eqversion:10.12.4

Trust: 0.3

vendor:applemodel:macosscope:eqversion:10.12.3

Trust: 0.3

vendor:applemodel:macosscope:eqversion:10.12.2

Trust: 0.3

vendor:applemodel:macosscope:eqversion:10.12.1

Trust: 0.3

vendor:applemodel:macosscope:eqversion:10.12

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.11.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.10.5

Trust: 0.3

vendor:applemodel:macosscope:neversion:10.12.5

Trust: 0.3

sources: BID: 98483 // JVNDB: JVNDB-2017-003849 // CNNVD: CNNVD-201705-963 // NVD: CVE-2017-6988

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6988
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6988
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201705-963
value: MEDIUM

Trust: 0.6

VULHUB: VHN-115191
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6988
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-115191
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6988
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-115191 // JVNDB: JVNDB-2017-003849 // CNNVD: CNNVD-201705-963 // NVD: CVE-2017-6988

PROBLEMTYPE DATA

problemtype:CWE-295

Trust: 1.9

sources: VULHUB: VHN-115191 // JVNDB: JVNDB-2017-003849 // NVD: CVE-2017-6988

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201705-963

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201705-963

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003849

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:HT207797url:https://support.apple.com/en-us/HT207797

Trust: 0.8

title:HT207797url:https://support.apple.com/ja-jp/HT207797

Trust: 0.8

title:Apple macOS Sierra 802.1X Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70439

Trust: 0.6

sources: JVNDB: JVNDB-2017-003849 // CNNVD: CNNVD-201705-963

EXTERNAL IDS

db:NVDid:CVE-2017-6988

Trust: 2.8

db:SECTRACKid:1038484

Trust: 1.1

db:JVNid:JVNVU98089541

Trust: 0.8

db:JVNDBid:JVNDB-2017-003849

Trust: 0.8

db:CNNVDid:CNNVD-201705-963

Trust: 0.7

db:BIDid:98483

Trust: 0.3

db:VULHUBid:VHN-115191

Trust: 0.1

sources: VULHUB: VHN-115191 // BID: 98483 // JVNDB: JVNDB-2017-003849 // CNNVD: CNNVD-201705-963 // NVD: CVE-2017-6988

REFERENCES

url:https://support.apple.com/ht207797

Trust: 1.7

url:http://www.securitytracker.com/id/1038484

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6988

Trust: 0.8

url:http://jvn.jp/vu/jvnvu98089541/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6988

Trust: 0.8

url:https://www.apple.com/

Trust: 0.3

sources: VULHUB: VHN-115191 // BID: 98483 // JVNDB: JVNDB-2017-003849 // CNNVD: CNNVD-201705-963 // NVD: CVE-2017-6988

CREDITS

Tim Cappalli of Aruba, Ian Beer of Google Project Zero, Samuel Gro? and Niklas Baumstark, Chaitin Security Research Lab, evi1m0 of YSRC, sss and Axis of 360Nirvan team, 360 Security, Jann Horn, Federico Bento of Faculty of Sciences, Richard Zhu, and Team

Trust: 0.3

sources: BID: 98483

SOURCES

db:VULHUBid:VHN-115191
db:BIDid:98483
db:JVNDBid:JVNDB-2017-003849
db:CNNVDid:CNNVD-201705-963
db:NVDid:CVE-2017-6988

LAST UPDATE DATE

2025-04-20T22:54:43.619000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-115191date:2017-07-08T00:00:00
db:BIDid:98483date:2017-05-15T00:00:00
db:JVNDBid:JVNDB-2017-003849date:2017-06-08T00:00:00
db:CNNVDid:CNNVD-201705-963date:2017-05-24T00:00:00
db:NVDid:CVE-2017-6988date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-115191date:2017-05-22T00:00:00
db:BIDid:98483date:2017-05-15T00:00:00
db:JVNDBid:JVNDB-2017-003849date:2017-06-08T00:00:00
db:CNNVDid:CNNVD-201705-963date:2017-05-24T00:00:00
db:NVDid:CVE-2017-6988date:2017-05-22T05:29:03.083