CVE-2021-1799:Port redirection vulnerability in Apple products allowing malicious websites to access restricted ports on arbitrary servers.

splash
Back

Description Preview

A security vulnerability identified as CVE-2021-1799 affects multiple Apple operating systems and Safari. The issue involves a port redirection flaw that could allow malicious websites to access restricted ports on arbitrary servers. This vulnerability could potentially be exploited to bypass same-origin policy restrictions and access services that should be protected. Apple addressed this vulnerability by implementing additional port validation measures in their affected products.

Overview

The vulnerability exists in multiple Apple products including macOS, iOS, iPadOS, tvOS, watchOS, and Safari. The flaw involves insufficient validation of network ports, which could allow a malicious website to redirect traffic to restricted ports on arbitrary servers. This could potentially enable attackers to probe internal networks, access sensitive services, or conduct server-side request forgery (SSRF) attacks. The issue affects all versions of the affected products prior to the security updates released by Apple in early 2021.

Remediation

To mitigate this vulnerability, users should update to the following versions or later:

  • macOS Big Sur 11.2
  • Security Update 2021-001 Catalina
  • Security Update 2021-001 Mojave
  • tvOS 14.4
  • watchOS 7.3
  • iOS 14.4
  • iPadOS 14.4
  • Safari 14.0.3

The updates implement additional port validation to prevent malicious websites from accessing restricted ports on arbitrary servers. It is recommended to apply these updates as soon as possible to protect against potential exploitation of this vulnerability.

References

  1. Apple Security Advisory for macOS: https://support.apple.com/en-us/HT212146
  2. Apple Security Advisory for iOS/iPadOS: https://support.apple.com/en-us/HT212149
  3. Apple Security Advisory for tvOS: https://support.apple.com/en-us/HT212147
  4. Apple Security Advisory for watchOS: https://support.apple.com/en-us/HT212148
  5. Apple Security Advisory for Safari: https://support.apple.com/en-us/HT212152
  6. Fedora Security Advisory: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JN6ZOD62CTO54CHTMJTHVEF6R2Y532TJ/
  7. Gentoo Linux Security Advisory: https://security.gentoo.org/glsa/202104-03

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Public Administration: Medium
    Public Administration
  2. Manufacturing: Medium
    Manufacturing
  3. Health Care & Social Assistance: Medium
    Health Care & Social Assistance
  4. Educational Services: Medium
    Educational Services
  5. Transportation & Warehousing: Medium
    Transportation & Warehousing
  6. Finance and Insurance: Medium
    Finance and Insurance
  7. Retail Trade: Medium
    Retail Trade
  8. Utilities: Medium
    Utilities
  9. Arts, Entertainment & Recreation: Low
    Arts, Entertainment & Recreation
  10. Professional, Scientific, & Technical Services: Low
    Professional, Scientific, & Technical Services
  11. Other Services (except Public Administration): Low
    Other Services (except Public Administration)
  12. Information: Low
    Information
  13. Management of Companies & Enterprises: Low
    Management of Companies & Enterprises
  14. Agriculture, Forestry Fishing & Hunting: Low
    Agriculture, Forestry Fishing & Hunting
  15. Real Estate Rental & Leasing: Low
    Real Estate Rental & Leasing
  16. Accommodation & Food Services: Low
    Accommodation & Food Services
  17. Mining: Low
    Mining
  18. Construction: Low
    Construction
  19. Administrative, Support, Waste Management & Remediation Services: Low
    Administrative, Support, Waste Management & Remediation Services
  20. Wholesale Trade: Low
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background