CVE-2011-3257
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.htmlVendor Advisory
- http://osvdb.org/76325
- http://support.apple.com/kb/HT4999Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70553
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.htmlVendor Advisory
- http://osvdb.org/76325
- http://support.apple.com/kb/HT4999Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70553
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.