VulnerabilityModified
CVE-2008-3612
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
CRITICAL 9.8EPSS 3.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.52% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- apple/iphone os
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00004.htmlMailing List, Vendor Advisory
- http://secunia.com/advisories/31823Broken Link, Vendor Advisory
- http://secunia.com/advisories/31900Broken Link, Vendor Advisory
- http://support.apple.com/kb/HT3026Vendor Advisory
- http://support.apple.com/kb/HT3129Vendor Advisory
- http://www.securityfocus.com/bid/31092Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020848Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2525Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2558Broken Link, Vendor Advisory
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00004.htmlMailing List, Vendor Advisory
- http://secunia.com/advisories/31823Broken Link, Vendor Advisory
- http://secunia.com/advisories/31900Broken Link, Vendor Advisory
- http://support.apple.com/kb/HT3026Vendor Advisory
- http://support.apple.com/kb/HT3129Vendor Advisory
- http://www.securityfocus.com/bid/31092Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020848Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2525Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2558Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.