CVE-2009-2794
 
Severity Score
4.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
El componente Exchange Support en Apple iPhome OS anteriores a la 3.1, e iPhone OS anteriores a 3.1.1 para iPod touch, no implementan de forma adecuada la funcionalidad de bloqueo por tiempo de inactividad máximo, lo que permite a usuarios locales saltarse las restricciones impuestas por Microsoft Exchange seleccionando un valor de tiempo grande para Requiere Passcode.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-08-17 CVE Reserved
- 2009-09-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/36342 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53181 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html | 2017-08-17 | |
http://support.apple.com/kb/HT3860 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/36677 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0 Search vendor "Apple" for product "Iphone Os" and version "2.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.0 Search vendor "Apple" for product "Iphone Os" and version "2.0.0" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.1 Search vendor "Apple" for product "Iphone Os" and version "2.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.1 Search vendor "Apple" for product "Iphone Os" and version "2.0.1" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.2 Search vendor "Apple" for product "Iphone Os" and version "2.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.2 Search vendor "Apple" for product "Iphone Os" and version "2.0.2" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1 Search vendor "Apple" for product "Iphone Os" and version "2.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1 Search vendor "Apple" for product "Iphone Os" and version "2.1" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1.1 Search vendor "Apple" for product "Iphone Os" and version "2.1.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2 Search vendor "Apple" for product "Iphone Os" and version "2.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2 Search vendor "Apple" for product "Iphone Os" and version "2.2" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2.1 Search vendor "Apple" for product "Iphone Os" and version "2.2.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2.1 Search vendor "Apple" for product "Iphone Os" and version "2.2.1" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 3.0 Search vendor "Apple" for product "Iphone Os" and version "3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 3.0 Search vendor "Apple" for product "Iphone Os" and version "3.0" | ipodtouch |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 3.0.1 Search vendor "Apple" for product "Iphone Os" and version "3.0.1" | - |
Affected
|