ID

VAR-201504-0124


CVE

CVE-2015-1108


TITLE

Apple iOS of Lock Screen Vulnerabilities that can gain access to components

Trust: 0.8

sources: JVNDB: JVNDB-2015-002149

DESCRIPTION

The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses. Apple iOS is prone to multiple security vulnerabilities. Attackers can exploit these issues to gain sensitive information, perform unauthorized actions, bypass security restrictions, and perform other attacks. These issues affect iOS versions prior to 8.3. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. Lock Screen is one of the screen lock components. The vulnerability stems from the program not properly limiting the number of password authentication attempts. An attacker could exploit this vulnerability to gain access by constructing multiple password guesses

Trust: 1.98

sources: NVD: CVE-2015-1108 // JVNDB: JVNDB-2015-002149 // BID: 73978 // VULHUB: VHN-79068

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.2

Trust: 1.0

vendor:applemodel:iosscope:ltversion:8.3 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.2

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

sources: BID: 73978 // JVNDB: JVNDB-2015-002149 // CNNVD: CNNVD-201504-133 // NVD: CVE-2015-1108

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1108
value: LOW

Trust: 1.0

NVD: CVE-2015-1108
value: LOW

Trust: 0.8

CNNVD: CNNVD-201504-133
value: LOW

Trust: 0.6

VULHUB: VHN-79068
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-1108
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-79068
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79068 // JVNDB: JVNDB-2015-002149 // CNNVD: CNNVD-201504-133 // NVD: CVE-2015-1108

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-79068 // JVNDB: JVNDB-2015-002149 // NVD: CVE-2015-1108

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201504-133

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201504-133

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002149

PATCH

title:APPLE-SA-2015-04-08-3 iOS 8.3url:http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html

Trust: 0.8

title:HT204661url:http://support.apple.com/en-us/HT204661

Trust: 0.8

title:HT204661url:http://support.apple.com/ja-jp/HT204661

Trust: 0.8

title:OSXUpd10.10.3url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54848

Trust: 0.6

title:iPhone7,1_8.3_12F70_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54847

Trust: 0.6

title:AppleTV3,2_7.2_12F69_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54849

Trust: 0.6

sources: JVNDB: JVNDB-2015-002149 // CNNVD: CNNVD-201504-133

EXTERNAL IDS

db:NVDid:CVE-2015-1108

Trust: 2.8

db:BIDid:73978

Trust: 1.4

db:SECTRACKid:1032050

Trust: 1.1

db:JVNid:JVNVU91828320

Trust: 0.8

db:JVNDBid:JVNDB-2015-002149

Trust: 0.8

db:CNNVDid:CNNVD-201504-133

Trust: 0.7

db:VULHUBid:VHN-79068

Trust: 0.1

sources: VULHUB: VHN-79068 // BID: 73978 // JVNDB: JVNDB-2015-002149 // CNNVD: CNNVD-201504-133 // NVD: CVE-2015-1108

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/apr/msg00002.html

Trust: 1.7

url:https://support.apple.com/ht204661

Trust: 1.7

url:http://www.securityfocus.com/bid/73978

Trust: 1.1

url:http://www.securitytracker.com/id/1032050

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1108

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91828320/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1108

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:https://support.apple.com/en-us/ht204661

Trust: 0.3

sources: VULHUB: VHN-79068 // BID: 73978 // JVNDB: JVNDB-2015-002149 // CNNVD: CNNVD-201504-133 // NVD: CVE-2015-1108

CREDITS

TaiG Jailbreak Team, Jarrod Dwenger, Steve Favorito, Paul Reedy of ConocoPhillips, Pedro Tavares of Molecular Biophysics at UCIBIO/FCT/UNL, De Paul Sunny, Christian Still of Evolve Media, Canada, Brent Erickson, Stuart Ryan of University of Technology, Syd

Trust: 0.3

sources: BID: 73978

SOURCES

db:VULHUBid:VHN-79068
db:BIDid:73978
db:JVNDBid:JVNDB-2015-002149
db:CNNVDid:CNNVD-201504-133
db:NVDid:CVE-2015-1108

LAST UPDATE DATE

2024-11-23T21:05:53.473000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79068date:2017-01-03T00:00:00
db:BIDid:73978date:2015-05-07T17:36:00
db:JVNDBid:JVNDB-2015-002149date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-133date:2015-04-14T00:00:00
db:NVDid:CVE-2015-1108date:2024-11-21T02:24:41.360

SOURCES RELEASE DATE

db:VULHUBid:VHN-79068date:2015-04-10T00:00:00
db:BIDid:73978date:2015-04-08T00:00:00
db:JVNDBid:JVNDB-2015-002149date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-133date:2015-04-14T00:00:00
db:NVDid:CVE-2015-1108date:2015-04-10T14:59:23.670