CVE-2017-2351: Input Validation
Wi-Fi. An issue existed with handling user input that caused a device to present the home screen even when activation locked. This was addressed through improved input validation.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WiFi" component, which allows physically proximate attackers to bypass the activation-lock protection mechanism and view the home screen via unspecified vectors.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-2351?
CVE-2017-2351 is considered a medium severity vulnerability due to its potential to allow unauthorized access to the home screen.
How do I fix CVE-2017-2351?
To fix CVE-2017-2351, upgrade your device to iOS version 10.2.1 or later.
What products are affected by CVE-2017-2351?
CVE-2017-2351 affects certain Apple products running iOS versions prior to 10.2.1.
What type of vulnerability is CVE-2017-2351?
CVE-2017-2351 is a user input handling vulnerability that compromises device activation lock.
When was CVE-2017-2351 disclosed?
CVE-2017-2351 was disclosed as part of the Apple security updates in January 2017.