CVE-2011-3430
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html
- http://osvdb.org/76330
- http://support.apple.com/kb/HT4999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70560
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html
- http://osvdb.org/76330
- http://support.apple.com/kb/HT4999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70560
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.