Lucene search

K
cveAppleCVE-2013-0963
HistoryJan 29, 2013 - 5:58 a.m.

CVE-2013-0963

2013-01-2905:58:54
CWE-20
apple
web.nvd.nist.gov
30
apple
ios
authentication bypass
certificate validation
cve-2013-0963
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

39.7%

Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.

Affected configurations

Nvd
Node
appleiphone_osRange6.0.2
OR
appleiphone_osMatch6.0
OR
appleiphone_osMatch6.0.1
VendorProductVersionCPE
appleiphone_oscpe:/o:apple:iphone_os::::
appleiphone_os6.0.1cpe:/o:apple:iphone_os:6.0.1:::
appleiphone_os6.0cpe:/o:apple:iphone_os:6.0:::

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

39.7%