LOW · 2.1

CVE-2015-5851

The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encr...

Vulnerability Description

The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleMac Os X<= 10.10.5
AppleIphone Os<= 8.4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-5851?

CVE-2015-5851 is a vulnerability with a CVSS score of 2.1 (LOW). The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encr...

How severe is CVE-2015-5851?

CVE-2015-5851 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-5851?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Apple Iphone Os.