Permissions, Privileges, and Access Controls in tvOS - CVE-2014-1383

 

Permissions, Privileges, and Access Controls in tvOS - CVE-2014-1383

Published: July 1, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41522
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1383
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.


Affected software

tvOS

How to mitigate CVE-2014-1383

Install update from vendor's website.


External References

Related Security Bulletins