The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iphone_os | Apple | * | 7.1.2 (including) |
Iphone_os | Apple | 7.0 (including) | 7.0 (including) |
Iphone_os | Apple | 7.0.1 (including) | 7.0.1 (including) |
Iphone_os | Apple | 7.0.2 (including) | 7.0.2 (including) |
Iphone_os | Apple | 7.0.3 (including) | 7.0.3 (including) |
Iphone_os | Apple | 7.0.4 (including) | 7.0.4 (including) |
Iphone_os | Apple | 7.0.5 (including) | 7.0.5 (including) |
Iphone_os | Apple | 7.0.6 (including) | 7.0.6 (including) |
Iphone_os | Apple | 7.1 (including) | 7.1 (including) |
Iphone_os | Apple | 7.1.1 (including) | 7.1.1 (including) |