CVE-2013-5193Apple Iphone OS vulnerability

CWE-2552 documents2 sources
Severity
4.7MEDIUMNVD
EPSS
0.0%
top 85.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMay 17

Description

The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID credentials.

CVSS vector

AV:L/AC:M/C:N/I:C/A:NExploitability: 3.4 | Impact: 6.9

Affected Packages1 packages

NVDapple/iphone_os7.0.3+3

🔴Vulnerability Details

1
GHSA
GHSA-56v6-3467-r5f7: The App Store component in Apple iOS before 72022-05-17
CVE-2013-5193 — Apple Iphone OS vulnerability | cvebase