CVE-2014-2019
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
18/02/2014
Last modified:
11/04/2025
Description
The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | 7.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtml
- http://support.apple.com/kb/HT6162
- http://www.youtube.com/watch?v=QnPk4RRWjic
- http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtml
- http://support.apple.com/kb/HT6162
- http://www.youtube.com/watch?v=QnPk4RRWjic



