Server-side request forgery in Apple HomeKit iOS



Published: 2017-12-08
Risk Low
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2017-13903
CWE-ID CWE-918
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Apple iOS
Operating systems & Components / Operating system

Vendor Apple Inc.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Server-side request forgery

EUVDB-ID: #VU9592

Risk: High

CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-13903

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

Exploit availability: No

Description

The vulnerability allows a remote user to perform SSRF attack.

The weakness exists due to unknown error. A remote attacker can perform SSRF attack to bypass network access controls, perform unauthorized connections to local resources, gain access to sensitive information and compromise vulnerable system.

Mitigation

Update to version 11.2.1.

Vulnerable software versions

Apple iOS: 11.2

External links

http://support.apple.com/en-us/HT208357


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###