CVE-2014-4366: Medium severity apple iPhone OS vulnerability
Published Sep 18, 2014
·Updated
Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Affected Software
10 affected components
apple iPhone OS<=7.1.2
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
apple iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4366?
CVE-2014-4366 has a medium severity rating due to the exposure of sensitive information.
2
How does CVE-2014-4366 impact users?
CVE-2014-4366 allows remote attackers to intercept sensitive cleartext information from users' Mail on iOS devices.
3
Which versions of Apple iOS are affected by CVE-2014-4366?
CVE-2014-4366 affects Apple iOS versions prior to 8, including all 7.x versions up to 7.1.1.
4
What is the recommended action to mitigate CVE-2014-4366?
To mitigate CVE-2014-4366, users should update their devices to at least iOS 8 or later.
5
Is there a workaround for CVE-2014-4366 if unable to update?
A temporary workaround for CVE-2014-4366 is to avoid using IMAP with servers that have LOGIN disabled.