CVE-2015-1109Sensitive Information Exposure in Apple Iphone OS

Severity
2.1LOWNVD
EPSS
0.1%
top 78.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateMay 17

Description

NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Appleapple/ios8.3

🔴Vulnerability Details

1
GHSA
GHSA-h6pq-4fqr-9hfg: NetworkExtension in Apple iOS before 82022-05-17

📋Vendor Advisories

1
Apple
CVE-2015-1109: iOS 8.3
CVE-2015-1109 — Sensitive Information Exposure in Apple | cvebase