CVE-2013-1028: Input Validation
The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1028?
CVE-2013-1028 has a moderate severity rating due to the risk of man-in-the-middle attacks.
How do I fix CVE-2013-1028?
To fix CVE-2013-1028, update your Apple Mac OS X to version 10.8.5 or later.
Which systems are affected by CVE-2013-1028?
CVE-2013-1028 affects Apple Mac OS X versions prior to 10.8.5 and iPhone OS versions up to 6.1.4.
What type of attack does CVE-2013-1028 allow?
CVE-2013-1028 allows attackers to spoof security gateways, potentially leading to sensitive information exposure.
How can I verify if my system is vulnerable to CVE-2013-1028?
You can verify if your system is vulnerable to CVE-2013-1028 by checking your operating system version against the known affected versions.