CVE-2009-2794
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange…
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- apple/iphone os
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/36677Vendor Advisory
- http://support.apple.com/kb/HT3860Patch, Vendor Advisory
- http://www.securityfocus.com/bid/36342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53181
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/36677Vendor Advisory
- http://support.apple.com/kb/HT3860Patch, Vendor Advisory
- http://www.securityfocus.com/bid/36342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53181
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.