Vulnerability Name:

CVE-2008-4230 (CCN-46761)

Assigned:2008-11-21
Published:2008-11-21
Updated:2022-08-09
Summary:The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages.
Note: this might be a duplicate of CVE-2008-4593.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-264
CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2008-4230

Source: APPLE
Type: UNKNOWN
APPLE-SA-2008-11-20

Source: OSVDB
Type: UNKNOWN
50027

Source: CCN
Type: SA32756
Apple iPhone / iPod touch Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
32756

Source: CCN
Type: Apple Web site
About the security content of iPhone OS 2.2 and iPhone OS for iPod touch 2.2

Source: CONFIRM
Type: Vendor Advisory
http://support.apple.com/kb/HT3318

Source: CCN
Type: OSVDB ID: 50027
Apple iPhone / iPod Touch Passcode Lock Bypass Short Message Service (SMS) Disclosure

Source: BID
Type: Vendor Advisory
32394

Source: CCN
Type: BID-32394
Apple iPhone and iPod touch Prior to Version 2.2 Multiple Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2008-3232

Source: XF
Type: UNKNOWN
apple-iphone-passcodelock-info-disclosure(46761)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:apple:ipod_touch:*:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:*
  • AND
  • cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple ipod touch *
    apple iphone os *
    apple iphone os 1.0.2
    apple iphone os 1.0
    apple iphone os 1.1.1
    apple iphone os 1.1.2
    apple iphone os 1.1.3
    apple iphone os 1.1
    apple iphone os 1.0.1
    apple iphone os 2.1
    apple iphone os 1.1.5
    apple iphone os 2.0.1
    apple iphone os 2.0
    apple iphone os 2.0.2
    apple iphone os 1.1.4
    apple iphone 1.1.4
    apple ipod touch 1.1.4
    apple ipod touch 2.0
    apple iphone 2.0
    apple iphone 2.1