Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2399

Опубликовано: 02 апр. 2017
Источник: nvd
CVSS3: 4.6
CVSS2: 2.1
EPSS Низкий

Описание

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Версия до 10.2.1 (включая)

EPSS

Процентиль: 5%
0.0002
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 4.6
github
больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).

fstec
почти 9 лет назад

Уязвимость операционной системы iOS, позволяющая нарушителю читать данные из буфера обмена

EPSS

Процентиль: 5%
0.0002
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-326