{"api_version":"1","generated_at":"2026-07-23T14:28:42+00:00","cve":"CVE-2011-3212","urls":{"html":"https://cve.report/CVE-2011-3212","api":"https://cve.report/api/cve/CVE-2011-3212.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-3212","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-3212"},"summary":{"title":"CVE-2011-3212","description":"CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.","state":"PUBLISHED","assigner":"apple","published_at":"2011-10-14 10:55:08","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html","name":"http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2011-10-12-3 OS X Lion v10.7.2 and Security Update 2011-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT5281","name":"http://support.apple.com/kb/HT5281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of OS X Lion v10.7.4 and Security Update 2012-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT5002","name":"http://support.apple.com/kb/HT5002","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of OS X Lion v10.7.2 and Security Update 2011-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/50085","name":"http://www.securityfocus.com/bid/50085","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X Prior to 10.7.2 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/76362","name":"http://osvdb.org/76362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2012-05-09-1 OS X Lion v10.7.4 and Security Update 2012-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-3212","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3212","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"3212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"3212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"3212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"3212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:29:56.688Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"76362","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/76362"},{"name":"APPLE-SA-2011-10-12-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT5002"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT5281"},{"name":"APPLE-SA-2012-05-09-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2012/May/msg00001.html"},{"name":"50085","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/50085"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-10-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-10-19T09:00:00.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"76362","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/76362"},{"name":"APPLE-SA-2011-10-12-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT5002"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT5281"},{"name":"APPLE-SA-2012-05-09-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2012/May/msg00001.html"},{"name":"50085","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/50085"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2011-3212","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"76362","refsource":"OSVDB","url":"http://osvdb.org/76362"},{"name":"APPLE-SA-2011-10-12-3","refsource":"APPLE","url":"http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"},{"name":"http://support.apple.com/kb/HT5002","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT5002"},{"name":"http://support.apple.com/kb/HT5281","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT5281"},{"name":"APPLE-SA-2012-05-09-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2012/May/msg00001.html"},{"name":"50085","refsource":"BID","url":"http://www.securityfocus.com/bid/50085"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2011-3212","datePublished":"2011-10-14T10:00:00.000Z","dateReserved":"2011-08-19T00:00:00.000Z","dateUpdated":"2024-08-06T23:29:56.688Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-10-14 10:55:08","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.7.0:*:*:*:*:*:*:*","matchCriteriaId":"8961F444-48C4-4B54-829B-A1A2D0F2716C"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.7.1:*:*:*:*:*:*:*","matchCriteriaId":"09A0FA11-6211-4962-A6E0-F00732818012"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.7.0:*:*:*:*:*:*:*","matchCriteriaId":"38823717-65A1-4587-8F05-32EA9A01084C"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.7.1:*:*:*:*:*:*:*","matchCriteriaId":"7BD4E77C-3F87-476B-BB66-75EECDFDB18E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"3212","Ordinal":"1","Title":"CVE-2011-3212","CVE":"CVE-2011-3212","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"3212","Ordinal":"1","NoteData":"CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.","Type":"Description","Title":"CVE-2011-3212"},{"CveYear":"2011","CveId":"3212","Ordinal":"2","NoteData":"2011-10-14","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"3212","Ordinal":"3","NoteData":"2011-10-19","Type":"Other","Title":"Modified"}]}}}