CVE-2016-7638

medium

Description

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.

References

http://www.securityfocus.com/bid/94850

http://www.securitytracker.com/id/1037429

https://support.apple.com/HT207422

Details

Source: MITRE

Published: 2017-02-20

Updated: 2017-07-27

Type: CWE-254

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 4.6

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 0.9

Severity: MEDIUM