CVE-2015-7094Improper Input Validation in Apple Iphone OS

Severity
2.6LOWNVD
EPSS
0.3%
top 43.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 17

Description

CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

🔴Vulnerability Details

1
GHSA
GHSA-53rm-9vx8-h5mq: CFNetwork HTTPProtocol in Apple iOS before 92022-05-17

📋Vendor Advisories

2
Apple
CVE-2015-7094: iOS 9.2
Apple
CVE-2015-7094: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks