CVE-2017-14315

UnknownEPSS 1.00%

Last modified

CVE-2017-14315 is a vulnerability of currently unknown severity. In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. EPSS estimates a 1.00% chance of exploitation in the next 30 days.

Description

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

Metrics

EPSS Probability
1.00%

58.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AppleIphone Os7.0
AppleIphone Os7.0.1
AppleIphone Os7.0.2
AppleIphone Os7.0.3
AppleIphone Os7.0.4
AppleIphone Os7.0.5
AppleIphone Os7.0.6
AppleIphone Os7.1
AppleIphone Os7.1.1
AppleIphone Os7.1.2
AppleIphone Os8.0
AppleIphone Os8.0.1
AppleIphone Os8.0.2
AppleIphone Os8.1
AppleIphone Os8.1.2
AppleIphone Os8.1.3
AppleIphone Os8.2
AppleIphone Os8.4.1
AppleIphone Os9.0
AppleIphone Os9.0.1
AppleIphone Os9.0.2
AppleIphone Os9.1
AppleIphone Os9.2
AppleIphone Os9.2.1
AppleIphone Os9.3
AppleIphone Os9.3.1
AppleIphone Os9.3.2
AppleIphone Os9.3.3
AppleIphone Os9.3.4
AppleIphone Os9.3.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-14315?
In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.
How severe is CVE-2017-14315?
Severity scoring for CVE-2017-14315 is pending analysis. The EPSS model estimates a 1.00% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14315?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-14315?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST