CVE-2017-2383

Description

An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the APNs Server component. It allows man-in-the-middle attackers to track users via correlation with this certificate.

Risk Information

Base Score
3.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.145

Associated Vulnerability

VulnerabilityOS Platform
Update for iCloud (6.2.1.67)Windows
Update for iCloud (6.2.2.39)Windows
iCloud 6.2.2.39Windows
Update for iCloud (6.2.3.17)Windows
Vulnerabilities CVE-2017-2383,CVE-2017-2480 are affected in Apple iTunes (X64) 12.5.5.5Windows
Vulnerabilities CVE-2017-2383,CVE-2017-2480 are affected in Apple iTunes 12.5.5.5Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-303316Update for iCloud (6.2.1.67)
PATCH-305759Update for iCloud (6.2.2.39)
PATCH-316162iCloud (7.21.0.23) (Deployment-Only)
PATCH-306105Update for iCloud (6.2.3.17)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234