PT-2018-5593 · Apple · Ios
Rorie Hood
·
Published
2018-04-03
·
Updated
2019-10-03
·
CVE-2017-13806
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
iOS versions prior to 11
Description:
An issue was discovered in certain Apple products, specifically involving the "Profiles" component. The issue is that the component does not enforce the configuration profile's settings for whether pairings are allowed.
Recommendations:
For iOS versions prior to 11, consider restricting the use of the "Profiles" component until a fix is available. As a temporary workaround, review and manually enforce configuration profile settings for pairings to minimize potential risks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ios