← Back

CVE-2014-1295

nvd nist
Published: Apr 23, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."

Affected (22)

3 products
Iphone Os
Mac Os X
Tvos
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 7.1
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.9.1
Version 10.9.2
Version 10.9
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 6.1
Version 6.0.1
Version 6.0.2
Version 6.0
Configuration D
7 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.8.0
Version 10.8.1
Version 10.8.2
Version 10.8.3
Version 10.8.4
Version 10.8.5
Version 10.8.5 supplemental_update

References (8)

Source: product-security@apple.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.