« Volver al listado

CVE-2013-0982

Estado: ModificadaBaja (1.7)—

The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-0982",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.7,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-06-05T14:39:55.443",
  "references": [
    {
      "url": "http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html",
      "source": "product-security@apple.com"
    },
    {
      "url": "http://support.apple.com/kb/HT5784",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT5784",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation."
    },
    {
      "lang": "es",
      "value": "La función de navegación privada en CFNetwork en Apple Mac OS X antes de v10.8.4 no impide el almacenamiento de cookies permanentes a la salida de Safari, que podría permitir a atacantes físicamente cercanos evitar la autenticación basada en cookies mediante el aprovechamiento de una estación de trabajo sin supervisión."
    }
  ],
  "lastModified": "2026-06-16T23:50:27.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8961F444-48C4-4B54-829B-A1A2D0F2716C"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09A0FA11-6211-4962-A6E0-F00732818012"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A36C17C-EBB3-4C42-9C75-6A7F2EE1F22C"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A82DEF28-B061-44B3-AF9B-BE529DB457D9"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFAECA7C-9A9F-4F5D-8E57-7334C34D24F7"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D318511-0594-4EE0-BA09-1FA110CFDD17"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38823717-65A1-4587-8F05-32EA9A01084C"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BD4E77C-3F87-476B-BB66-75EECDFDB18E"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCDC2BD4-B8DB-4B23-82E3-9D2D7A32CBFE"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "910034A6-3A04-404A-A5BC-D33BD15DCB91"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85625414-1AA5-4523-99C0-E27359B568E4"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8751C7BF-EDDA-4B23-9BE4-5F62B409198D"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "489D0901-5D6A-4AA2-B80B-3E706FF1742D",
              "versionEndIncluding": "10.8.3"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2082D62-3821-4DBA-8690-67489F44C38D"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F0DB1BC-DC16-423E-B0C7-8E9C996A50B5"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:10.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E59315BA-B9F1-46A5-86E7-8BE2ED97BA4F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}