CVE-2014-1266

HIGH

Apple Iphone OS < 6.1.6 - Improper Certificate Validation

Title source: rule
STIX 2.1

Description

The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple OS X 10.9.x before 10.9.2 does not check the signature in a TLS Server Key Exchange message, which allows man-in-the-middle attackers to spoof SSL servers by (1) using an arbitrary private key for the signing step or (2) omitting the signing step.

Exploits (4)

nomisec WORKING POC 78 stars
by gabrielg · poc
https://github.com/gabrielg/CVE-2014-1266-poc
nomisec WRITEUP 26 stars
by landonf · poc
https://github.com/landonf/Testability-CVE-2014-1266
nomisec WORKING POC 1 stars
by macressler · poc
https://github.com/macressler/SSLPatch
nomisec NO CODE
by meetlight942 · poc
https://github.com/meetlight942/PentesterLab-Intercept-CVE-2014-1266

References (9)

Core 9
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6147
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6148
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6146
Exploit, Issue Tracking x_refsource_misc
https://news.ycombinator.com/item?id=7281378

Scores

CVSS v3 7.4
EPSS 0.1790
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (3)
apple/iphone_os 6.0 - 6.1.6
apple/mac_os_x 10.9 - 10.9.2
apple/tvos 6.0 - 6.0.2
Published Feb 22, 2014
Tracked Since Feb 18, 2026