VulnerabilityModified
CVE-2013-5164
Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.
LOW 3.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.