VulnerabilityModified
CVE-2017-2411
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS.
MEDIUM 5.9EPSS 0.75%
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- https://support.apple.com/HT208334Vendor Advisory
- https://support.apple.com/HT208334Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.