CVE-2024-54492

MEDIUM

iPadOS < 17.7.3 - Network Traffic Tampering via Unencrypted HTTP

Title source: llm
STIX 2.1

Description

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.

Scores

CVSS v3 5.9
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

Status published
Products (8)
Apple/iOS and iPadOS < 18.2
apple/ipados < 17.7.3
Apple/iPadOS < 17.7.3
apple/iphone_os < 18.2
apple/macos < 15.2
Apple/macOS < 15.2
apple/visionos < 2.2
Apple/visionOS < 2.2
Published Dec 12, 2024
Tracked Since Feb 18, 2026