Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.
CVSS Details
- CVSS 3.1 Base Score: 4.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Jan 29, 2013 |
| Apple Osx Identityservices | — | Upgrade macOS to the latest versionApply OS X security update 2013-001 | Apr 3, 2013 | Jan 29, 2013 |
| Apple Osx Note | — | Apply OS X security update 2013-001Upgrade macOS to the latest versionApply OS X security update 2013-002 | Aug 28, 2015 | Jan 29, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub