CVE-2017-2414 is a vulnerability affecting iOS versions prior to 10.3, specifically within the DataAccess component. It allows remote attackers to opportunistically access Exchange traffic if a user makes a typing mistake when entering an email address. The vulnerability has a CVSS v3 score of 5.3 (Medium), indicating a low impact on integrity (I:L) with network access (AV:N) and low attack complexity (AC:L), requiring no user interaction (UI:N). While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, including a Threatpost article detailing its potential to expose email passwords.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.