CVE-2017-2399 is a medium-severity vulnerability affecting iOS versions prior to 10.3. It allows a physically proximate attacker to read the device's pasteboard due to an encryption key being derived solely from the hardware UID. The CVSS score is 4.6, indicating a low attack complexity and no user interaction required, with a high impact on confidentiality. There is no known exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability has received no community discussion or media coverage, suggesting it is not actively exploited or widely known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.