Логотип exploitDog
bind:CVE-2017-14315
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-14315

Количество 3

Количество 3

nvd логотип

CVE-2017-14315

больше 8 лет назад

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fh2g-g7qm-3vm4

больше 3 лет назад

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2017-02055

больше 8 лет назад

Уязвимость протокола Low Energy Audio Protocol (LEAP) операционной системы iOS, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-14315

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
github логотип
GHSA-fh2g-g7qm-3vm4

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2017-02055

Уязвимость протокола Low Energy Audio Protocol (LEAP) операционной системы iOS, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.9
0%
Низкий
больше 8 лет назад

Уязвимостей на страницу