{"api_version":"1","generated_at":"2026-07-23T10:23:36+00:00","cve":"CVE-2014-1360","urls":{"html":"https://cve.report/CVE-2014-1360","api":"https://cve.report/api/cve/CVE-2014-1360.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-1360","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-1360"},"summary":{"title":"CVE-2014-1360","description":"Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.","state":"PUBLISHED","assigner":"apple","published_at":"2014-07-01 10:17:26","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68276","name":"http://www.securityfocus.com/bid/68276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS Prior to 7.1.2 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT6441","name":"http://support.apple.com/kb/HT6441","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of iOS 8 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030500","name":"http://www.securitytracker.com/id/1030500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Let Local Applications Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-1360","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1360","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1360","vulnerable":"1","versionEndIncluding":"7.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:42:34.940Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT6441"},{"name":"68276","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68276"},{"name":"APPLE-SA-2014-06-30-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html"},{"name":"APPLE-SA-2014-09-17-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"name":"1030500","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030500"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-06-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-04T17:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT6441"},{"name":"68276","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68276"},{"name":"APPLE-SA-2014-06-30-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html"},{"name":"APPLE-SA-2014-09-17-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"name":"1030500","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030500"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2014-1360","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.apple.com/kb/HT6441","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT6441"},{"name":"68276","refsource":"BID","url":"http://www.securityfocus.com/bid/68276"},{"name":"APPLE-SA-2014-06-30-3","refsource":"APPLE","url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html"},{"name":"APPLE-SA-2014-09-17-1","refsource":"APPLE","url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"name":"1030500","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030500"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2014-1360","datePublished":"2014-07-01T10:00:00.000Z","dateReserved":"2014-01-08T00:00:00.000Z","dateUpdated":"2024-08-06T09:42:34.940Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-01 10:17:26","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1.1","matchCriteriaId":"E8E92C81-A564-4B9A-A263-8C0CF7844D32"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0:*:*:*:*:*:*:*","matchCriteriaId":"07A11433-B725-4BD6-B998-4B3637F061EC"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"4FD62141-07B1-4E3D-80BC-25D519F90DBD"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.2:*:*:*:*:*:*:*","matchCriteriaId":"D9737BD4-B4F4-4291-A1E9-B692ECBC657E"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.3:*:*:*:*:*:*:*","matchCriteriaId":"B6160869-944D-4E34-BB81-6A1259D692B1"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.4:*:*:*:*:*:*:*","matchCriteriaId":"090CAC3C-4B20-46E5-A8C7-950B7E1DB5E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.5:*:*:*:*:*:*:*","matchCriteriaId":"E96F77DD-0962-4E55-97A2-9BC2FE01D8A8"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.0.6:*:*:*:*:*:*:*","matchCriteriaId":"8BD9ACBF-34A4-4181-A6E0-78ABD4FC9ACB"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:7.1:*:*:*:*:*:*:*","matchCriteriaId":"EDF40E86-E5D2-4D66-B296-ADFA78B42113"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"1360","Ordinal":"1","Title":"CVE-2014-1360","CVE":"CVE-2014-1360","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"1360","Ordinal":"1","NoteData":"Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.","Type":"Description","Title":"CVE-2014-1360"},{"CveYear":"2014","CveId":"1360","Ordinal":"2","NoteData":"2014-07-01","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"1360","Ordinal":"3","NoteData":"2017-01-04","Type":"Other","Title":"Modified"}]}}}