CVE-2017-7088
published 2017-10-23CVE-2017-7088: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.88%
77.3th percentile
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 10.3.3 | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c857-2vfc-6jrh: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-17
CVE-2017-7088 [HIGH] GHSA-c857-2vfc-6jrh: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
Apple
CVE-2017-7088: iOS 11
vendor_apple·2017-09-19·CVSS 5.9
CVE-2017-7088 [MEDIUM] CVE-2017-7088: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7088
Component: Exchange ActiveSync
Impact: An attacker in a privileged network position may be able to erase a device during Exchange account setup
Description: A validation issue existed in AutoDiscover V1. This was addressed by requiring TLS for AutoDiscover V1. AutoDiscover V2 is now supported.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-23
Published