PT-2017-1760 · Apple · Icloud+1

Matthias Wachs

+1

·

Published

2017-04-01

·

Updated

2017-07-12

·

CVE-2017-2383

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iTunes before 12.6 on Windows iCloud before 6.2 on Windows
Description The issue involves cleartext client-certificate transmission in the "APNs Server" component, allowing man-in-the-middle attackers to track users via correlation with this certificate. This is related to the use of plaintext client certificates and their transmission to a vulnerable component.
Recommendations For iTunes before 12.6 on Windows, update to version 12.6 or later to resolve the issue. For iCloud before 6.2 on Windows, update to version 6.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00916
CVE-2017-2383

Affected Products

Icloud
Itunes