CVE-2013-5193: Medium severity iphone os vulnerability
The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5193?
CVE-2013-5193 is considered a high severity vulnerability due to its ability to bypass security mechanisms in Apple's App Store.
How do I fix CVE-2013-5193?
To mitigate CVE-2013-5193, users should update their iOS devices to version 7.0.4 or higher.
Who is affected by CVE-2013-5193?
CVE-2013-5193 affects users of Apple iOS versions prior to 7.0.4, particularly those using older devices.
What types of transactions are vulnerable due to CVE-2013-5193?
CVE-2013-5193 allows unauthorized completion of both App and In-App purchases without proper authentication.
Is there a workaround for CVE-2013-5193?
There is no specific workaround for CVE-2013-5193 other than updating to the latest software version to secure the device.