Vulnerability Name: | CVE-2013-3948 (CCN-84806) | ||||||||
Assigned: | 2013-06-05 | ||||||||
Published: | 2013-06-05 | ||||||||
Updated: | 2014-03-16 | ||||||||
Summary: | Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services:// URL that leverages an open redirect vulnerability within a trusted domain. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: Stefan Esser Mountain Lion/iOS Vulnerabilities Garage Sale Source: MISC Type: Exploit http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdf Source: MITRE Type: CNA CVE-2013-3948 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT6162 Source: CCN Type: Apple Web site Apple Source: MISC Type: UNKNOWN http://www.syscan.org/index.php/sg/program/day/2 Source: XF Type: UNKNOWN appleios-cve20133948-sec-bypass(84806) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |