CVE Vulnerabilities

CVE-2017-2428

Published: Apr 02, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves nghttp2 before 1.17.0 in the HTTPProtocol component. It allows remote HTTP/2 servers to have an unspecified impact via unknown vectors.

Affected Software

NameVendorStart VersionEnd Version
Iphone_osApple*10.2.1 (including)
Mac_os_xApple*10.12.3 (including)
TvosApple*10.1.1 (including)
WatchosApple*3.1.3 (including)
Nghttp2Ubuntuyakkety*

References