Lucene search

K
cveF-SecureUSCVE-2021-33595
HistoryAug 11, 2021 - 11:15 a.m.

CVE-2021-33595

2021-08-1111:15:09
F-SecureUS
web.nvd.nist.gov
32
cve-2021-33595
address bar spoofing
safe browser
ios
vulnerability
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

42.9%

A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack.

Affected configurations

Nvd
Node
f-securesafeRange<18.4.272901iphone_os
VendorProductVersionCPE
f-securesafe*cpe:2.3:a:f-secure:safe:*:*:*:*:*:iphone_os:*:*

CNA Affected

[
  {
    "platforms": [
      "iOS"
    ],
    "product": "F-Secure Mobile Security",
    "vendor": "F-Secure",
    "versions": [
      {
        "lessThan": "18.3x*",
        "status": "affected",
        "version": "18.4x",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

42.9%

Related for CVE-2021-33595