CVE-2014-4449 describes a critical vulnerability in Apple iOS before version 8.1, where iCloud data access failed to properly validate X.509 certificates from TLS servers. This flaw allowed man-in-the-middle attackers to spoof legitimate servers using crafted certificates, potentially leading to the compromise of sensitive user information. With a CVSS score of 6.8, this vulnerability was moderately severe, requiring medium attack complexity but allowing for partial compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.