Vulnerabilities > CVE-2016-4642 - 7PK - Security Features vulnerability in Apple Iphone OS

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
apple
CWE-254
nessus

Summary

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

Vulnerable Configurations

Part Description Count
OS
Apple
145
Application
Apple
43

Common Weakness Enumeration (CWE)

Nessus

NASL familyMisc.
NASL idAPPLETV_9_2_2.NASL
descriptionAccording to its banner, the version of the remote Apple TV device is prior to 9.2.2. It is, therefore, affected by multiple vulnerabilities in the following components : - CoreGraphics - ImageIO - IOAcceleratorFamily - IOHIDFamily - Kernel - libxml2 - libxslt - Sandbox Profiles - WebKit - WebKit Page Loading Note that only 4th generation models are affected by the vulnerabilities.
last seen2020-06-01
modified2020-06-02
plugin id92494
published2016-07-21
reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/92494
titleApple TV < 9.2.2 Multiple Vulnerabilities