Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
BID:65738
Info
Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
| Bugtraq ID: | 65738 |
| Class: | Design Error |
| CVE: |
CVE-2014-1266 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Feb 21 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
Apple iOS and TV are prone to a security-bypass vulnerability because it fails to properly validate connections.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Apple iOS and TV are prone to a security-bypass vulnerability because it fails to properly validate connections.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apple iOS And TV Secure Transport Connection Validation Security Bypass Vulnerability
References:
References:
- Apple iOS Homepage (Apple)
- Apple TV Homepage (Apple)