CVE-2014-1361 describes a vulnerability in Apple's Secure Transport, affecting iOS before 7.1.2, OS X before 10.9.4, and Apple TV before 6.1.2. This flaw allows remote attackers to obtain potentially sensitive information from uninitialized process memory. The vulnerability arises because the system fails to ensure that a DTLS message is accepted only for a DTLS connection, permitting a DTLS message within a TLS connection. Rated with a CVSS score of 5.0, this vulnerability has a low attack complexity and requires no authentication, making it easily exploitable remotely over the network. The primary impact is a partial loss of confidentiality (C:P), as attackers could gain access to sensitive information. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating a low level of public awareness or concern regarding this specific vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.9CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.9:*:*:*:*:*:*:* | ||
10.9.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.9.1:*:*:*:*:*:*:* | ||
10.9.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.9.2:*:*:*:*:*:*:* | ||
10.9.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.9.3:*:*:*:*:*:*:* | ||
<= 7.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.