First published: Mon Jan 23 2017(Updated: )
APNs Server. A client certificate was sent in plaintext. This issue was addressed through improved certificate handling.
Credit: Matthias Wachs Quirin Scheitle Technical University Munich product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <10.2.1 | 10.2.1 |
Apple iCloud | <=6.1.1 | |
Apple iTunes | <=12.5.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2383 has a moderate severity level due to the potential exposure of sensitive client certificate information.
To fix CVE-2017-2383, update affected Apple software to the latest versions, specifically iOS 10.2.1, iCloud 6.2 or higher, and iTunes 12.6 or higher.
CVE-2017-2383 affects iCloud versions prior to 6.2, iTunes versions prior to 12.6, and iOS versions up to 10.2.1.
CVE-2017-2383 is a crypto vulnerability involving the transmission of client certificates in plaintext.
Yes, CVE-2017-2383 requires immediate attention to mitigate risks associated with exposed client certificates.