CVE-2014-4352: Low severity apple iPhone OS vulnerability
Published Sep 18, 2014
·Updated
Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
Affected Software
10 affected components
apple iPhone OS<=7.1.2
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
apple iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4352?
The severity of CVE-2014-4352 is considered moderate due to the potential for sensitive information exposure.
2
How do I fix CVE-2014-4352?
To fix CVE-2014-4352, users should update their devices to iOS version 8 or later.
3
What types of devices are affected by CVE-2014-4352?
CVE-2014-4352 affects Apple iOS devices running versions 7.1.2 and earlier.
4
What are the risks associated with CVE-2014-4352?
The risks associated with CVE-2014-4352 include unauthorized access to sensitive data through physical proximity.
5
Is there a workaround for CVE-2014-4352?
There are no specific workarounds for CVE-2014-4352; upgrading to a secure version is recommended.