CVE-2013-5186: Low severity Apple iOS and macOS vulnerability
Published Oct 24, 2013
·Updated
Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between locking and power assertions, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state.
Affected Software
7 affected components
Apple iOS and macOS<=10.8.5
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Apple iOS and macOS=10.8.5
Event History
Oct 24, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5186?
CVE-2013-5186 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-5186?
To fix CVE-2013-5186, upgrade to Mac OS X version 10.9 or later.
3
What type of vulnerability is CVE-2013-5186?
CVE-2013-5186 is a local information disclosure vulnerability.
4
Who is affected by CVE-2013-5186?
Users of Apple Mac OS X versions prior to 10.9 are affected by CVE-2013-5186.
5
What can an attacker do with CVE-2013-5186?
An attacker can potentially read sensitive information from a screen that should be locked due to improper handling of power assertions.