CVE-2017-2411Apple Iphone OS vulnerability

CWE-2543 documents3 sources
Severity
5.9MEDIUMNVD
EPSS
0.3%
top 44.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateMay 14

Description

In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDapple/iphone_os< 11.2
Appleapple/ios11.2

🔴Vulnerability Details

1
GHSA
GHSA-h452-vqm5-458m: In iOS before 112022-05-14

📋Vendor Advisories

1
Apple
CVE-2017-2411: iOS 11.22017-12-02