CVE-2017-14315
Last modified
CVE-2017-14315 is a vulnerability of currently unknown severity. In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | 7.0 |
| Apple | Iphone Os | 7.0.1 |
| Apple | Iphone Os | 7.0.2 |
| Apple | Iphone Os | 7.0.3 |
| Apple | Iphone Os | 7.0.4 |
| Apple | Iphone Os | 7.0.5 |
| Apple | Iphone Os | 7.0.6 |
| Apple | Iphone Os | 7.1 |
| Apple | Iphone Os | 7.1.1 |
| Apple | Iphone Os | 7.1.2 |
| Apple | Iphone Os | 8.0 |
| Apple | Iphone Os | 8.0.1 |
| Apple | Iphone Os | 8.0.2 |
| Apple | Iphone Os | 8.1 |
| Apple | Iphone Os | 8.1.2 |
| Apple | Iphone Os | 8.1.3 |
| Apple | Iphone Os | 8.2 |
| Apple | Iphone Os | 8.4.1 |
| Apple | Iphone Os | 9.0 |
| Apple | Iphone Os | 9.0.1 |
| Apple | Iphone Os | 9.0.2 |
| Apple | Iphone Os | 9.1 |
| Apple | Iphone Os | 9.2 |
| Apple | Iphone Os | 9.2.1 |
| Apple | Iphone Os | 9.3 |
| Apple | Iphone Os | 9.3.1 |
| Apple | Iphone Os | 9.3.2 |
| Apple | Iphone Os | 9.3.3 |
| Apple | Iphone Os | 9.3.4 |
| Apple | Iphone Os | 9.3.5 |
References
- http://www.securityfocus.com/bid/100816Third Party Advisory, VDB Entry
- https://www.armis.com/blueborneTechnical Description, Third Party Advisory
- http://www.securityfocus.com/bid/100816Third Party Advisory, VDB Entry
- https://www.armis.com/blueborneTechnical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14315?
How severe is CVE-2017-14315?
How do I fix CVE-2017-14315?
Are you affected by CVE-2017-14315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
