PT-2018-5593 · Apple · Ios

Rorie Hood

·

Published

2018-04-03

·

Updated

2019-10-03

·

CVE-2017-13806

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: iOS versions prior to 11
Description: An issue was discovered in certain Apple products, specifically involving the "Profiles" component. The issue is that the component does not enforce the configuration profile's settings for whether pairings are allowed.
Recommendations: For iOS versions prior to 11, consider restricting the use of the "Profiles" component until a fix is available. As a temporary workaround, review and manually enforce configuration profile settings for pairings to minimize potential risks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-13806

Affected Products

Ios