Vulnerability Name:

CVE-2008-3612 (CCN-45010)

Assigned:2008-09-09
Published:2008-09-09
Updated:2011-06-20
Summary:The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-189
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2008-3612

Source: APPLE
Type: Vendor Advisory
APPLE-SA-2008-09-09

Source: APPLE
Type: Vendor Advisory
APPLE-SA-2008-09-12

Source: CCN
Type: SA31823
Apple iPod Touch Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
31823

Source: CCN
Type: SA31900
Apple iPhone Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
31900

Source: CCN
Type: SECTRACK ID: 1020848
Apple iPod touch Generates Predictable TCP Sequence Numbers

Source: CCN
Type: Apple Web site
About the security content of iPod touch v2.1

Source: CONFIRM
Type: Vendor Advisory
http://support.apple.com/kb/HT3026

Source: CONFIRM
Type: Vendor Advisory
http://support.apple.com/kb/HT3129

Source: CCN
Type: OSVDB ID: 48044
Apple iPod Touch Networking Subsystem TCP Sequence Prediction

Source: CCN
Type: BID-31089
GEAR Software CD DVD Filter Driver 'GEARAspiWDM.sys' Local Privilege Escalation Vulnerability

Source: BID
Type: UNKNOWN
31092

Source: CCN
Type: BID-31092
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1020848

Source: VUPEN
Type: Vendor Advisory
ADV-2008-2525

Source: VUPEN
Type: Vendor Advisory
ADV-2008-2558

Source: XF
Type: UNKNOWN
apple-ipod-tcp-spoofing(45010)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple iphone 2.0
    apple iphone 2.0.1
    apple iphone 2.0.2
    apple ipod touch 2.0
    apple ipod touch 2.0.1
    apple ipod touch 2.0.2
    apple ipod touch 2.0.2
    apple ipod touch 2.0.1
    apple ipod touch 2.0
    apple iphone 1.0
    apple iphone 1.1.2
    apple iphone 1.1.3
    apple iphone 1.0.1
    apple iphone 1.1.1
    apple iphone 1.1.4
    apple iphone 2.0.2
    apple iphone 2.0
    apple iphone 2.0.1