7.5

CVE-2009-3273

iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.

Data is provided by the National Vulnerability Database (NVD)
AppleiPhone OS Version1.0
AppleiPhone OS Version1.0.0
AppleiPhone OS Version1.0.1
AppleiPhone OS Version1.0.1 Update- Editioniphone
AppleiPhone OS Version1.0.2
AppleiPhone OS Version1.0.2 Update- Editioniphone
AppleiPhone OS Version1.1
AppleiPhone OS Version1.1.0
AppleiPhone OS Version1.1.0 Update- Editioniphone
AppleiPhone OS Version1.1.0 Update- Editionipodtouch
AppleiPhone OS Version1.1.1
AppleiPhone OS Version1.1.1 Update- Editioniphone
AppleiPhone OS Version1.1.2
AppleiPhone OS Version1.1.2 Update- Editioniphone
AppleiPhone OS Version1.1.2 Update- Editionipodtouch
AppleiPhone OS Version1.1.3
AppleiPhone OS Version1.1.3 Update- Editioniphone
AppleiPhone OS Version1.1.3 Update- Editionipodtouch
AppleiPhone OS Version1.1.4
AppleiPhone OS Version1.1.4 Update- Editioniphone
AppleiPhone OS Version1.1.4 Update- Editionipodtouch
AppleiPhone OS Version1.1.5
AppleiPhone OS Version1.1.5 Update- Editioniphone
AppleiPhone OS Version1.1.5 Update- Editionipodtouch
AppleiPhone OS Version2.0
AppleiPhone OS Version2.0.0
AppleiPhone OS Version2.0.0 Update- Editioniphone
AppleiPhone OS Version2.0.0 Update- Editionipodtouch
AppleiPhone OS Version2.0.1
AppleiPhone OS Version2.0.1 Update- Editioniphone
AppleiPhone OS Version2.0.1 Update- Editionipodtouch
AppleiPhone OS Version2.0.2
AppleiPhone OS Version2.0.2 Update- Editioniphone
AppleiPhone OS Version2.0.2 Update- Editionipodtouch
AppleiPhone OS Version2.1
AppleiPhone OS Version2.1 Update- Editioniphone
AppleiPhone OS Version2.1 Update- Editionipodtouch
AppleiPhone OS Version2.1.1
AppleiPhone OS Version2.2
AppleiPhone OS Version2.2 Update- Editioniphone
AppleiPhone OS Version2.2 Update- Editionipodtouch
AppleiPhone OS Version2.2.1
AppleiPhone OS Version2.2.1 Update- Editioniphone
AppleiPhone OS Version2.2.1 Update- Editionipodtouch
AppleiPhone OS Version3.0
AppleiPhone OS Version3.0 Update- Editionipodtouch
AppleiPhone OS Version3.0.1
AppleiPhone OS Version3.0.1 Update- Editioniphone
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.363
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P