CVE-2007-3754
Published Sep 27, 2007
Last updated 2 years ago
Overview
- Description
- Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:apple:iphone:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F382364-1B45-4C62-AB29-A20512AA77D9" }, { "criteria": "cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C5B94E7-2C24-4913-B65E-8D8A0DE2B80B" }, { "criteria": "cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E28FB0CB-D636-4F85-B5F7-70EC30053925" } ], "operator": "OR" } ] } ]