CVE-2014-2019 describes a bypass vulnerability in the iCloud subsystem of Apple iOS before version 7.1. This flaw allows a physically proximate attacker to disable Find My iPhone or disassociate an Apple ID by entering an arbitrary password and a blank account description. Rated Medium with a CVSS score of 4.6, the vulnerability requires physical access and impacts the integrity of the device's iCloud settings. There is no evidence of active exploitation, nor are there known public exploits or Metasploit modules available. Community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.