CVE-2014-1285: Medium severity apple iPhone OS vulnerability
Published Mar 14, 2014
·Updated
Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.
Affected Software
7 affected components
apple iPhone OS<=7.0.6
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
Event History
Mar 14, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1285?
CVE-2014-1285 has a high severity rating, indicating a significant security risk.
2
How do I fix CVE-2014-1285?
To fix CVE-2014-1285, update your Apple iOS device to version 7.1 or later.
3
Which versions of Apple iOS are affected by CVE-2014-1285?
CVE-2014-1285 affects Apple iOS versions prior to 7.1, specifically versions 7.0 and 7.0.x.
4
What type of attack does CVE-2014-1285 enable?
CVE-2014-1285 enables physical attackers to bypass access restrictions and view the home screen of an unactivated device.
5
Can CVE-2014-1285 be exploited remotely?
No, CVE-2014-1285 requires physical proximity to the device to be exploited.