Vulnerabilities > CVE-2015-3756 - 7PK - Security Features vulnerability in Apple Iphone OS
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html
- http://www.securityfocus.com/bid/76337
- http://www.securityfocus.com/bid/76337
- http://www.securitytracker.com/id/1033275
- http://www.securitytracker.com/id/1033275
- https://support.apple.com/kb/HT205030
- https://support.apple.com/kb/HT205030