Vulnerability Description
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
CVSS Score
5.9
MEDIUM
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | < 11.2 |
Related Weaknesses (CWE)
References
- https://support.apple.com/HT208334Vendor Advisory
- https://support.apple.com/HT208334Vendor Advisory
FAQ
What is CVE-2017-2411?
CVE-2017-2411 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
How severe is CVE-2017-2411?
CVE-2017-2411 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2411?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Iphone Os.