vendor:
iOS
by:
Andy Davis
7.5
CVSS
HIGH
Arbitrary code execution
CWE
Product Name: iOS
Affected Version From: iOS 7.0
Affected Version To: iOS 7.0
Patch Exists: YES
Related CWE: CVE-2014-1287
CPE:
Platforms Tested: iPhone 4 and later, iPod touch (5th generation) and later, iPad 2 and later
2014
iOS 7 arbitrary code execution in kernel mode
When a specific value is supplied in USB Endpoint descriptor for a HID device, the Apple device kernel panics and reboots.
Mitigation:
Fixed in a later version