CVE-2011-0199
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
- Affected products
- Macos X
- Apple Mac Os X
- < 10.6.8
- Apple Mac Os X Server
- < 10.6.8
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 0.8% (52th percentile)
- Weakness
- CWE-295
- NVD status
- Modified
- Published
- 2011-06-24
CVE-2011-0199 at NVD
1 known exploit for CVE-2011-0199
Proof-of-concept code and exploit modules indexed by Sploitus