CVE-2008-4230
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages. NOTE: this might be a duplicate of CVE-2008-4593.
- CVSS 2.0
- 1.9 LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-264
- Affected
- apple/iphone os
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
- http://osvdb.org/50027
- http://secunia.com/advisories/32756
- http://support.apple.com/kb/HT3318Vendor Advisory
- http://www.securityfocus.com/bid/32394Vendor Advisory
- http://www.vupen.com/english/advisories/2008/3232
- http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
- http://osvdb.org/50027
- http://secunia.com/advisories/32756
- http://support.apple.com/kb/HT3318Vendor Advisory
- http://www.securityfocus.com/bid/32394Vendor Advisory
- http://www.vupen.com/english/advisories/2008/3232
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.