CVE-2014-2019

MEDIUM

iPhone OS < 7.1 - Unauthenticated iCloud Account Hijack via Blank Description Bypass

Title source: llm
STIX 2.1

Description

The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6162
Exploit, Third Party Advisory x_refsource_misc
http://www.youtube.com/watch?v=QnPk4RRWjic

Scores

CVSS v3 4.6
EPSS 0.0046
EPSS Percentile 37.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-264
Status published
Products (1)
apple/iphone_os < 7.1
Published Feb 18, 2014
Tracked Since Feb 18, 2026