Vulnerability Name: | CVE-2011-0228 (CCN-68781) |
Assigned: | 2010-12-23 |
Published: | 2011-07-26 |
Updated: | 2018-10-10 |
Summary: | The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-20
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2011-0228
Source: APPLE Type: Vendor Advisory APPLE-SA-2011-07-25-2
Source: APPLE Type: Vendor Advisory APPLE-SA-2011-07-25-1
Source: CCN Type: SA45369 Apple iOS "basicConstraints" X.509 Certificate Chain Validation Vulnerability
Source: SECUNIA Type: Vendor Advisory 45369
Source: SREASON Type: UNKNOWN 8361
Source: SECTRACK Type: UNKNOWN 1025837
Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4824
Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT4825
Source: CCN Type: Apple Web Site iPhone
Source: CCN Type: OSVDB ID: 74030 Apple iOS X.509 Certificate Chain Validation basicConstraints Parameter MitM Information Disclosure
Source: BUGTRAQ Type: UNKNOWN 20110725 TWSL2011-007: iOS SSL Implementation Does Not Validate Certificate Chain
Source: BID Type: UNKNOWN 48877
Source: CCN Type: BID-48877 Apple iOS Data Security Certificate Chain Validation Security Vulnerability
Source: XF Type: UNKNOWN appleios-x509-spoofing(68781)
Source: MISC Type: UNKNOWN https://www.trustwave.com/spiderlabs/advisories/TWSL2011-007.txt
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.8:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version <= 4.2.9) Configuration 2: cpe:/o:apple:ios:4.3.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.3:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.4:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:apple:ios:4.3.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.3:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |