Vulnerability Name: | CCN-102611 | ||||||
Published: | 2015-04-22 | ||||||
Updated: | 2015-04-22 | ||||||
Summary: | Apple iOS could allow a local attacker to bypass security restrictions, caused by an error in the favorite contact preview function. An attacker could exploit this vulnerability using siri to bypass the regular pass code restriction and gain access to the device. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Full Disclosure Mailing List, Wed, 22 Apr 2015 10:48:20 +0200 Apple iOS 8.0 - 8.0.2 - Controls Re Auth Bypass Vulnerability Source: CCN Type: Apple Web site iOS Source: XF Type: UNKNOWN appleios-preview-sec-bypass(102611) Source: CCN Type: Packet Storm Security [04-22-2015] Apple iOS 8.0.2 Authentication Bypass | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |