[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50129-6

Platform: cpe:/o:apple:mac_os_13Date: (C)2024-04-17   (M)2024-04-17



Apple provides the capability to manage macOS, iOS and iPadOS using Mobile Device Management (MDM). Profiles are used to configure devices to enforce security controls as well as to configure the devices for authorized access. Many security controls available on Apple devices are only available through the use of profile settings using MDM. This capability is also misused by attackers who have added rogue profiles to the list of unwanted software and fake software updates to induce users to approve the installation of malicious content. Organizations should have Mobile Device management software in place to harden organizationally managed devices and take advantage of additional Apple controls as well as to make the devices more resistant to attackers enticing users to install unwanted content from rogue MDMs. Rationale: Mobile Device Management is the preferred Apple method to manage Apple devices. Some capability in this technology is a requirement for the enforcement of some controls. Users with managed devices should be trained and familiar with authrized content provided through the organizations' MDM. Impact: An MDM is yet another additional tool that requires technically adept personnel to manage correctly. In theory proper use of an MDM can make services provisioning simpler with configuration profiles to reach authorized services. Remediation: Enroll the system in a Mobile Device Management software.


Parameter:

[Yes/No]


Technical Mechanism:

Remediation: Enroll the system in a Mobile Device Management software.

CCSS Severity:CCSS Metrics:
CCSS Score : 8.1Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 5.9Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99069


OVAL    1
oval:org.secpod.oval:def:99069
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_13

© SecPod Technologies