{"api_version":"1","generated_at":"2026-07-23T13:35:48+00:00","cve":"CVE-2014-4425","urls":{"html":"https://cve.report/CVE-2014-4425","api":"https://cve.report/api/cve/CVE-2014-4425.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-4425","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-4425"},"summary":{"title":"CVE-2014-4425","description":"CFPreferences in Apple OS X before 10.10 does not properly enforce the \"require password after sleep or screen saver begins\" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.","state":"PUBLISHED","assigner":"apple","published_at":"2014-10-18 01:55:12","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://support.apple.com/kb/HT6535","name":"https://support.apple.com/kb/HT6535","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of OS X Yosemite v10.10 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031063","name":"http://www.securitytracker.com/id/1031063","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple OS X Multiple Flaws Let Users Execute Arbitrary Code, Obtain Elevated Privileges, Bypass Security Restrictions, and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97640","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97640","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/70630","name":"http://www.securityfocus.com/bid/70630","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X CVE-2014-4425 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-4425","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-4425","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"4425","vulnerable":"1","versionEndIncluding":"10.9.5","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:12:35.689Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"macosx-cve20144425-sec-bypass(97640)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97640"},{"name":"APPLE-SA-2014-10-16-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html"},{"name":"1031063","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031063"},{"name":"70630","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/70630"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT6535"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-10-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"CFPreferences in Apple OS X before 10.10 does not properly enforce the \"require password after sleep or screen saver begins\" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"macosx-cve20144425-sec-bypass(97640)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97640"},{"name":"APPLE-SA-2014-10-16-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html"},{"name":"1031063","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031063"},{"name":"70630","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/70630"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT6535"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2014-4425","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CFPreferences in Apple OS X before 10.10 does not properly enforce the \"require password after sleep or screen saver begins\" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"macosx-cve20144425-sec-bypass(97640)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97640"},{"name":"APPLE-SA-2014-10-16-1","refsource":"APPLE","url":"http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html"},{"name":"1031063","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031063"},{"name":"70630","refsource":"BID","url":"http://www.securityfocus.com/bid/70630"},{"name":"https://support.apple.com/kb/HT6535","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT6535"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2014-4425","datePublished":"2014-10-18T01:00:00.000Z","dateReserved":"2014-06-20T00:00:00.000Z","dateUpdated":"2024-08-06T11:12:35.689Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-10-18 01:55:12","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionEndIncluding":"10.9.5","matchCriteriaId":"9C3A0363-F05A-49C3-A9D2-E4F31B60CD4D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"4425","Ordinal":"1","Title":"CVE-2014-4425","CVE":"CVE-2014-4425","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"4425","Ordinal":"1","NoteData":"CFPreferences in Apple OS X before 10.10 does not properly enforce the \"require password after sleep or screen saver begins\" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.","Type":"Description","Title":"CVE-2014-4425"},{"CveYear":"2014","CveId":"4425","Ordinal":"2","NoteData":"2014-10-17","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"4425","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}