PT-2014-5834 · Apple · Tv+1

Bram Bonne

+3

·

Published

2014-09-18

·

Updated

2019-03-08

·

CVE-2014-4364

CVSS v2.0

2.9

Low

VectorAV:A/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 8 Apple TV versions prior to 7
Description The issue concerns the 802.1X subsystem, which does not enforce strong authentication methods. This allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
Recommendations For Apple iOS versions prior to 8, update to version 8 or later to resolve the issue. For Apple TV versions prior to 7, update to version 7 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4364

Affected Products

Tv
Ios