Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1067

Опубликовано: 11 мар. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-1637.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Версия до 10.10.2 (включая)
Конфигурация 2
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
Версия до 7.0.3 (включая)
Конфигурация 3
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Версия до 8.1.3 (включая)

EPSS

Процентиль: 89%
0.04799
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-1637.

EPSS

Процентиль: 89%
0.04799
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310