Vulnerabilities > Apple > Software Update > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-03-14 CVE-2016-1731 Insufficient Verification of Data Authenticity vulnerability in Apple Software Update
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
network
high complexity
apple CWE-345
5.9