CVE-2015-5851: Infoleak
Published Sep 18, 2015
·Updated
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.
Affected Software
2 affected components
Apple iOS and macOS<=10.10.5
Apple iPhone OS<=8.4.1
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5851?
CVE-2015-5851 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-5851?
To mitigate CVE-2015-5851, upgrade to a version of iOS or macOS that is 9.0 or later.
3
What does CVE-2015-5851 exploit in iOS and macOS?
CVE-2015-5851 exploits the lack of encryption requirement in the Multipeer Connectivity component.
4
Who is affected by CVE-2015-5851?
Users of iOS versions prior to 9.0 and macOS versions up to 10.10.5 are affected by CVE-2015-5851.
5
What is an encrypted-to-unencrypted downgrade attack in relation to CVE-2015-5851?
An encrypted-to-unencrypted downgrade attack allows local users to access cleartext multipeer data due to the vulnerability in session encryption.