CVE-2017-2383
02.04.2017, 01:59
An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the "APNs Server" component. It allows man-in-the-middle attackers to track users via correlation with this certificate.Enginsight
Vendor | Product | Version |
---|---|---|
apple | icloud | 𝑥 ≤ 6.1.1 |
apple | itunes | 𝑥 ≤ 12.5.5.5 |
𝑥
= Vulnerable software versions
References