Vulnerabilities > CVE-2017-13903 - Unspecified vulnerability in Apple Iphone OS
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 is affected. The issue involves the "HomeKit" component. It allows remote attackers to modify the application state by leveraging incorrect message handling, as demonstrated by use of an Apple Watch to obtain an encryption key and unlock a door.
Vulnerable Configurations
References
- http://www.securityfocus.com/bid/102182
- http://www.securityfocus.com/bid/102182
- http://www.securitytracker.com/id/1040008
- http://www.securitytracker.com/id/1040008
- https://support.apple.com/HT208357
- https://support.apple.com/HT208357
- https://support.apple.com/HT208359
- https://support.apple.com/HT208359
- https://www.engadget.com/2017/12/21/apple-ignored-a-major-homekit-security-flaw-for-six-weeks/
- https://www.engadget.com/2017/12/21/apple-ignored-a-major-homekit-security-flaw-for-six-weeks/