cbcvebase.
CVE-2014-4364
published 2014-09-18

CVE-2014-4364: The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate…

PriorityP428medium5.6CVSS 3.0
AVAACHPRNUIRSCCHINAN
EPSS
0.81%
53.2th percentile
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.

Affected

17 ranges
VendorProductVersion rangeFixed in
appleiphone_os<= 7.1.2
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appleiphone_os
appletvos<= 6.2
appletvos
appletvos
appletvos
appletvos
appletvos
appletvos

CVSS provenance

nvdv3.05.6MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.