ID

VAR-201504-0125


CVE

CVE-2015-1109


TITLE

Apple iOS of NetworkExtension Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2015-002150

DESCRIPTION

NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file. Apple iOS is prone to multiple security vulnerabilities. Attackers can exploit these issues to gain sensitive information, perform unauthorized actions, bypass security restrictions, and perform other attacks. These issues affect iOS versions prior to 8.3. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. A security vulnerability exists in Apple iOS 8.2 and earlier versions of NetworkExtension, the vulnerability stems from storing certificates in VPN configuration files

Trust: 1.98

sources: NVD: CVE-2015-1109 // JVNDB: JVNDB-2015-002150 // BID: 73978 // VULHUB: VHN-79069

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.2

Trust: 1.0

vendor:applemodel:iosscope:ltversion:8.3 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.2

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

sources: BID: 73978 // JVNDB: JVNDB-2015-002150 // CNNVD: CNNVD-201504-134 // NVD: CVE-2015-1109

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1109
value: LOW

Trust: 1.0

NVD: CVE-2015-1109
value: LOW

Trust: 0.8

CNNVD: CNNVD-201504-134
value: LOW

Trust: 0.6

VULHUB: VHN-79069
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-1109
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-79069
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79069 // JVNDB: JVNDB-2015-002150 // CNNVD: CNNVD-201504-134 // NVD: CVE-2015-1109

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-79069 // JVNDB: JVNDB-2015-002150 // NVD: CVE-2015-1109

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201504-134

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201504-134

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002150

PATCH

title:APPLE-SA-2015-04-08-3 iOS 8.3url:http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html

Trust: 0.8

title:HT204661url:http://support.apple.com/en-us/HT204661

Trust: 0.8

title:HT204661url:http://support.apple.com/ja-jp/HT204661

Trust: 0.8

sources: JVNDB: JVNDB-2015-002150

EXTERNAL IDS

db:NVDid:CVE-2015-1109

Trust: 2.8

db:BIDid:73978

Trust: 1.4

db:SECTRACKid:1032050

Trust: 1.1

db:JVNid:JVNVU91828320

Trust: 0.8

db:JVNDBid:JVNDB-2015-002150

Trust: 0.8

db:CNNVDid:CNNVD-201504-134

Trust: 0.7

db:VULHUBid:VHN-79069

Trust: 0.1

sources: VULHUB: VHN-79069 // BID: 73978 // JVNDB: JVNDB-2015-002150 // CNNVD: CNNVD-201504-134 // NVD: CVE-2015-1109

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/apr/msg00002.html

Trust: 1.7

url:https://support.apple.com/ht204661

Trust: 1.7

url:http://www.securityfocus.com/bid/73978

Trust: 1.1

url:http://www.securitytracker.com/id/1032050

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1109

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91828320/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1109

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:https://support.apple.com/en-us/ht204661

Trust: 0.3

sources: VULHUB: VHN-79069 // BID: 73978 // JVNDB: JVNDB-2015-002150 // CNNVD: CNNVD-201504-134 // NVD: CVE-2015-1109

CREDITS

TaiG Jailbreak Team, Jarrod Dwenger, Steve Favorito, Paul Reedy of ConocoPhillips, Pedro Tavares of Molecular Biophysics at UCIBIO/FCT/UNL, De Paul Sunny, Christian Still of Evolve Media, Canada, Brent Erickson, Stuart Ryan of University of Technology, Syd

Trust: 0.3

sources: BID: 73978

SOURCES

db:VULHUBid:VHN-79069
db:BIDid:73978
db:JVNDBid:JVNDB-2015-002150
db:CNNVDid:CNNVD-201504-134
db:NVDid:CVE-2015-1109

LAST UPDATE DATE

2024-11-23T20:50:15.584000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79069date:2017-01-03T00:00:00
db:BIDid:73978date:2015-05-07T17:36:00
db:JVNDBid:JVNDB-2015-002150date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-134date:2015-04-13T00:00:00
db:NVDid:CVE-2015-1109date:2024-11-21T02:24:41.483

SOURCES RELEASE DATE

db:VULHUBid:VHN-79069date:2015-04-10T00:00:00
db:BIDid:73978date:2015-04-08T00:00:00
db:JVNDBid:JVNDB-2015-002150date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-134date:2015-04-13T00:00:00
db:NVDid:CVE-2015-1109date:2015-04-10T14:59:24.483