VulnerabilityModified
CVE-2015-5770
MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.
MEDIUM 5.8EPSS 1.48%
Does this matter?
Lower severity and a low EPSS score (1.48%). Track it; it rarely justifies an emergency change on its own.
Description
MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 1.48% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlVendor Advisory
- http://www.securityfocus.com/bid/76337
- http://www.securitytracker.com/id/1033275
- https://support.apple.com/kb/HT205030Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlVendor Advisory
- http://www.securityfocus.com/bid/76337
- http://www.securitytracker.com/id/1033275
- https://support.apple.com/kb/HT205030Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.