Man-in-the-Middle Attack Vulnerability in Apple Mac OS X WebDAV Communication

Man-in-the-Middle Attack Vulnerability in Apple Mac OS X WebDAV Communication

CVE-2011-3213 · HIGH Severity

AV:N/AC:H/AU:N/C:C/I:C/A:C

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

Learn more about our Web App Pen Testing.