CVE-2014-4364: Medium severity iPhone OS vulnerability
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4364?
CVE-2014-4364 is classified as a high severity vulnerability due to the potential for remote credential theft.
How do I fix CVE-2014-4364?
To address CVE-2014-4364, it is recommended to upgrade to Apple iOS version 8 or later.
What systems are affected by CVE-2014-4364?
CVE-2014-4364 affects Apple iOS versions prior to 8 and Apple TV versions prior to 7.
What type of attack is possible with CVE-2014-4364?
CVE-2014-4364 allows remote attackers to exploit weakened authentication methods to calculate user credentials.
Is there a workaround for CVE-2014-4364?
There are no specific workarounds for CVE-2014-4364, so users should upgrade their devices to mitigate risk.