{"api_version":"1","generated_at":"2026-07-23T04:20:13+00:00","cve":"CVE-2017-7149","urls":{"html":"https://cve.report/CVE-2017-7149","api":"https://cve.report/api/cve/CVE-2017-7149.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7149","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7149"},"summary":{"title":"CVE-2017-7149","description":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"StorageKit\" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2017-10-23 01:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/101178","name":"101178","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Apple macOS CVE-2017-7149 Local Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/","name":"https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"Crazy but true – Apple’s “show hint” button reveals your actual password – Naked Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79","name":"https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"New macOS High Sierra vulnerability exposes the password of an encrypted APFS container","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039513","name":"1039513","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple macOS/OS X Disk Utility Hint Field Lets Local Users View the Password for an Encrypted APFS Volume - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT208165","name":"https://support.apple.com/HT208165","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of macOS High Sierra 10.13 Supplemental Update - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/","name":"https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/","refsource":"MISC","tags":["Exploit","Press/Media Coverage","Third Party Advisory"],"title":"Dumb bug of the week: Apple's macOS reveals your encrypted drive's password in the hint box • The Register","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7149","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7149","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7149","vulnerable":"1","versionEndIncluding":"10.13","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2017-7149","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"StorageKit\" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79","refsource":"MISC","url":"https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79"},{"name":"https://support.apple.com/HT208165","refsource":"CONFIRM","url":"https://support.apple.com/HT208165"},{"name":"1039513","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039513"},{"name":"https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/","refsource":"MISC","url":"https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/"},{"name":"101178","refsource":"BID","url":"http://www.securityfocus.com/bid/101178"},{"name":"https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/","refsource":"MISC","url":"https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/"}]}},"nvd":{"publishedDate":"2017-10-23 01:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionEndIncluding":"10.13","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7149","Ordinal":"103844","Title":"CVE-2017-7149","CVE":"CVE-2017-7149","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7149","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"StorageKit\" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"7149","Ordinal":"2","NoteData":"2017-10-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7149","Ordinal":"3","NoteData":"2017-10-23","Type":"Other","Title":"Modified"}]}}}