CVE-2016-4741
published 2016-09-18CVE-2016-4741: The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for…
PriorityP425medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.43%
70.2th percentile
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.5 | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m76v-c6vg-3px3: The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS sessi
ghsa_unreviewed·2022-05-17
CVE-2016-4741 [MEDIUM] GHSA-m76v-c6vg-3px3: The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS sessi
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
Apple
CVE-2016-4741: iOS 10
vendor_apple·2016-09-13·CVSS 5.9
CVE-2016-4741 [MEDIUM] CVE-2016-4741: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4741
Component: Assets
Impact: An attacker in a privileged network position may be able to block a device from receiving software updates
Description: An issue existed in iOS updates, which did not properly secure user communications. This issue was addressed by using HTTPS for software updates.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143
2016-09-18
Published