VDB
CVE-2008-3438
CVE-2008-3438
PUBLISHED
CVSS 8.100000381469727 HIGH
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
EPSS 0.83% · 54.1th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.83%
54.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | mac_os_x | 10.0.0 |
Timeline
- Aug 1, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf url
- http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz url
- 20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-3438 advisory