Vulnerability Name: | CVE-2013-0963 (CCN-81557) | ||||||||
Assigned: | 2013-01-28 | ||||||||
Published: | 2013-01-28 | ||||||||
Updated: | 2013-03-16 | ||||||||
Summary: | Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-0963 Source: APPLE Type: Vendor Advisory APPLE-SA-2013-01-28-1 Source: APPLE Type: UNKNOWN APPLE-SA-2013-03-14-1 Source: CCN Type: SA52002 Apple iOS Multiple Vulnerabilities Source: CCN Type: Apple Web site About the security content of iOS 6.1 Software Update Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT5642 Source: CCN Type: BID-57598 Apple iPhone/iPad/iPod touch Prior to iOS 6.1 CVE-2013-0963 Security Bypass Vulnerability Source: XF Type: UNKNOWN apple-identityservices-cve20130963(81557) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |