PT-2017-1760 · Apple · Icloud+1

Matthias Wachs

+1

·

Publicado

2017-04-01

·

Atualizado

2017-07-12

·

CVE-2017-2383

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iTunes before 12.6 on Windows iCloud before 6.2 on Windows
Description The issue involves cleartext client-certificate transmission in the "APNs Server" component, allowing man-in-the-middle attackers to track users via correlation with this certificate. This is related to the use of plaintext client certificates and their transmission to a vulnerable component.
Recommendations For iTunes before 12.6 on Windows, update to version 12.6 or later to resolve the issue. For iCloud before 6.2 on Windows, update to version 6.2 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00916
CVE-2017-2383

Produtos afetados

Icloud
Itunes