CVE-2012-3721: Medium severity apple ios and macos vulnerability
Published Sep 20, 2012
·Updated
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.
Affected Software
71 affected components
Apple iOS and macOS<=10.7.4
Apple iOS and macOS=10.0
Apple iOS and macOS=10.0.0
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1
Apple iOS and macOS=10.1.0
Apple iOS and macOS=10.1.1
Apple iOS and macOS=10.1.2
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.1.5
Apple iOS and macOS=10.2
Apple iOS and macOS=10.2.0
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.0
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.0
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.5
Apple iOS and macOS=10.5.0
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.5.2
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.4
Apple iOS and macOS=10.5.5
Apple iOS and macOS=10.5.6
Apple iOS and macOS=10.5.7
Apple iOS and macOS=10.5.8
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.3
Apple iOS and macOS=10.6.4
Apple iOS and macOS=10.6.5
Apple iOS and macOS=10.6.6
Apple iOS and macOS=10.6.7
Apple iOS and macOS=10.6.8
Apple iOS and macOS=10.7.0
Apple iOS and macOS=10.7.1
Apple iOS and macOS=10.7.2
Apple iOS and macOS=10.7.3
Event History
Sep 20, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3721?
CVE-2012-3721 is classified as a moderate severity vulnerability due to its potential impact on device enumeration.
2
How do I fix CVE-2012-3721?
To fix CVE-2012-3721, you should upgrade to Apple Mac OS X version 10.7.5 or later.
3
What type of attack does CVE-2012-3721 facilitate?
CVE-2012-3721 facilitates unauthorized enumeration of managed devices through weak authentication.
4
Which versions of Mac OS X are affected by CVE-2012-3721?
CVE-2012-3721 affects Mac OS X versions prior to 10.7.5.
5
Is authentication properly enforced in CVE-2012-3721?
No, CVE-2012-3721 indicates that authentication is not properly enforced in the Device Management private interface.