ZeroHour

CVE-2017-2380

CVSS 3.0
7.5 high
EPSS
<1%p52
Published
()
Modified
Description

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the Simple Certificate Enrollment Protocol (SCEP) implementation in the "Profiles" component. It allows remote attackers to bypass cryptographic protection mechanisms by leveraging DES support.

Vendors
apple
Products
iphone os
Weakness
CWE-326
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.