{ "schema_version": "1.4.0", "id": "GHSA-xxgg-95mq-2fw5", "modified": "2022-05-13T01:54:04Z", "published": "2022-05-13T01:54:04Z", "aliases": [ "CVE-2014-2019" ], "details": "The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-2019" }, { "type": "WEB", "url": "http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtml" }, { "type": "WEB", "url": "http://support.apple.com/kb/HT6162" }, { "type": "WEB", "url": "http://www.youtube.com/watch?v=QnPk4RRWjic" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-02-18T11:55:00Z" } }