CVE-2021-33595 Vulnerability Details

  /     /     /  

CVE-2021-33595 Metadata Quick Info

CVE Published: 11/08/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: F-SecureUS | Vendor: F-Secure | Product: F-Secure Mobile Security
Status : PUBLISHED

CVE-2021-33595 Description

A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack.

Metrics

CVSS Version: 3.1 | Base Score: 3.5 LOW
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: F-Secure Safe browser for iOS vulnerable to Address Bar Spoofing
Source: F-Secure

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).