Permissions, Privileges, and Access Controls in tvOS - CVE-2014-1383
Published: July 1, 2014 / Updated: August 10, 2020
Vulnerability identifier: #VU41522
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1383
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to read and manipulate data.
Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.
Affected software
tvOS
How to mitigate CVE-2014-1383
Install update from vendor's website.