CVE-2014-2019
The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different…
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/iphone os
- Source
- cve@mitre.org
References
- http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtmlThird Party Advisory
- http://support.apple.com/kb/HT6162Vendor Advisory
- http://www.youtube.com/watch?v=QnPk4RRWjicExploit, Third Party Advisory
- http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtmlThird Party Advisory
- http://support.apple.com/kb/HT6162Vendor Advisory
- http://www.youtube.com/watch?v=QnPk4RRWjicExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.