CVE-2014-1383: Medium severity tvos vulnerability
Published Jul 1, 2014
·Updated
Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.
Affected Software
5 affected components
tvOS<=6.1.1
tvOS=6.0
tvOS=6.0.1
tvOS=6.0.2
tvOS=6.1
Event History
Jul 1, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1383?
The severity of CVE-2014-1383 is considered moderate due to the risk of unauthorized purchase transactions.
2
How do I fix CVE-2014-1383?
To fix CVE-2014-1383, update your Apple TV to version 6.1.2 or later.
3
Who is affected by CVE-2014-1383?
Users running Apple TV versions 6.1.1 and earlier are affected by CVE-2014-1383.
4
What type of attack does CVE-2014-1383 involve?
CVE-2014-1383 involves bypassing a password requirement for iTunes Store purchases.
5
Is CVE-2014-1383 a remote vulnerability?
Yes, CVE-2014-1383 allows remote authenticated users to exploit the vulnerability.