MEDIUM · 5.8

CVE-2014-1267

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass ...

Vulnerability Description

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass intended access restrictions by using a profile after the date has passed.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AppleTvos<= 6.0.2
AppleIphone Os<= 7.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1267?

CVE-2014-1267 is a vulnerability with a CVSS score of 5.8 (MEDIUM). The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass ...

How severe is CVE-2014-1267?

CVE-2014-1267 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1267?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Tvos, Apple Iphone Os.