CVE-2015-3756

The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:29

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html - Vendor Advisory () http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html - Vendor Advisory
References () http://www.securityfocus.com/bid/76337 - () http://www.securityfocus.com/bid/76337 -
References () http://www.securitytracker.com/id/1033275 - () http://www.securitytracker.com/id/1033275 -
References () https://support.apple.com/kb/HT205030 - Vendor Advisory () https://support.apple.com/kb/HT205030 - Vendor Advisory

Information

Published : 2015-08-16 23:59

Updated : 2024-11-21 02:29


NVD link : CVE-2015-3756

Mitre link : CVE-2015-3756

CVE.ORG link : CVE-2015-3756


JSON object : View

Products Affected

apple

  • iphone_os
CWE
CWE-254

7PK - Security Features