CVE-2017-2485 is a critical vulnerability affecting Apple's iOS before 10.3, macOS before 10.12.4, tvOS before 10.2, and watchOS before 3.2, specifically within the "Security" component. This flaw allows remote attackers to execute arbitrary code or trigger a denial of service through memory corruption and application crashes by presenting a specially crafted X.509 certificate file. With a CVSS score of 8.8 (High), it indicates a network-based attack with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is identified, and it's not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.12.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
<= 3.1.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.