Lucene search

K
nessusThis script is Copyright (C) 2012-2024 and is owned by Tenable, Inc. or an Affiliate thereof.APPLE_IOS_511_CHECK.NBIN
HistoryFeb 14, 2012 - 12:00 a.m.

Apple iOS < 5.1.1 Multiple Vulnerabilities

2012-02-1400:00:00
This script is Copyright (C) 2012-2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
13

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.02 Low

EPSS

Percentile

88.8%

The mobile device is running a version of iOS that is older than version 5.1.1. Version 5.1.1 contains numerous security-related fixes for the following vulnerabilities :

  • Attackers can use a vulnerability in WebKit to perform cross-site scripting attacks, possibly leaking data such as cookies, user information, and passwords.
    (CVE-2011-3046, CVE-2011-3056)

  • A remote code execution vulnerability in WebKit could allow a malicious site to run code on the host iOS device giving the attacker access to critical data on the phone.(CVE-2012-0672)

  • Vulnerabilities in Safari can allow malicious sites to spoof the address in the address bar of the browser.
    This attack allows an attacker to redirect victims to a malicious site without the user’s ability to notice.
    (CVE-2012-0674)

Binary data apple_ios_511_check.nbin
VendorProductVersionCPE
appleiphone_oscpe:/o:apple:iphone_os

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.02 Low

EPSS

Percentile

88.8%