CVE-2017-2411
published 2019-01-11CVE-2017-2411: In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
PriorityP425medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
0.75%
51.1th percentile
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11.2 | 11.2 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-2411: iOS 11.2
vendor_apple·2017-12-02·CVSS 5.9
CVE-2017-2411 [MEDIUM] CVE-2017-2411: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-2411
Component: Calculator
Impact: An attacker with a privileged network position may be able to alter currency conversion rates
Description: Exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
GHSA
GHSA-h452-vqm5-458m: In iOS before 11
ghsa_unreviewed·2022-05-14
CVE-2017-2411 [MEDIUM] GHSA-h452-vqm5-458m: In iOS before 11
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-11
Published