CVE-2021-30657
medium · 5.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2021-11-17
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
5.5
CVSS
68.5%
EPSS (exploit prob.)
99th
EPSS percentile
2021-09-08
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weaknesses
CWE-862
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | mac_os_x | >= 10.15, <= 10.15.5 |
| apple | mac_os_x | 10.15.6 |
| apple | mac_os_x | 10.15.6 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | macos | >= 11.0, < 11.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-30657