CVE-2017-7078Cleartext Transmission of Sensitive Info in Apple Iphone OS

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 56.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 13

Description

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" component. It allows remote attackers to obtain sensitive information by reading unintended cleartext transmissions.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDapple/mac_os_x10.12.6
NVDapple/iphone_os10.3.3
Appleapple/ios11

🔴Vulnerability Details

1
GHSA
GHSA-vxrj-g732-gg2h: An issue was discovered in certain Apple products2022-05-13

💥Exploits & PoCs

1
Exploit-DB
EasyCom For PHP 4.0.0 - Denial of Service2017-02-22

📋Vendor Advisories

2
Apple
CVE-2017-7078: macOS High Sierra 10.132017-09-25
Apple
CVE-2017-7078: iOS 112017-09-19

💬Community

1
Bugzilla
CVE-2016-7078 foreman: Information leak through organizations and locations feature2016-10-18