Description
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5797 | The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack. |
References
History
No history.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T07:06:33.942Z
Reserved: 2015-08-06T00:00:00.000Z
Link: CVE-2015-5851
No data.
Status : Modified
Published: 2015-09-18T11:00:04.297
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-5851
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD