CVE-2013-0963
Last modified
CVE-2013-0963 is a vulnerability of currently unknown severity. Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | <= 6.0.2 |
| Apple | Iphone Os | 6.0 |
| Apple | Iphone Os | 6.0.1 |
References
- http://support.apple.com/kb/HT5642Vendor Advisory
- http://support.apple.com/kb/HT5642Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0963?
How severe is CVE-2013-0963?
How do I fix CVE-2013-0963?
Are you affected by CVE-2013-0963?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
