CVE-2015-5898
published 2015-09-18CVE-2015-5898: CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.25%
16.3th percentile
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | iphone_os | <= 8.4.1 | — |
| apple | watchos | — | — |
| apple | watchos_2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-5898: watchOS 2
vendor_apple·CVSS 2.1
CVE-2015-5898 [LOW] CVE-2015-5898: watchOS 2
Apple Security Update: About the security content of watchOS 2
Product: watchOS 2
CVE: CVE-2015-5898
Component: CVE-ID
Apple
CVE-2015-5898: iOS 9
vendor_apple·CVSS 2.1
CVE-2015-5898 [LOW] CVE-2015-5898: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2015-5898
Component: CVE-ID
GHSA
GHSA-vjgx-8ggj-99mf: CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to o
ghsa_unreviewed·2022-05-17
CVE-2015-5898 [LOW] CWE-200 GHSA-vjgx-8ggj-99mf: CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to o
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://www.securityfocus.com/bid/76764http://www.securitytracker.com/id/1033609https://support.apple.com/HT205212https://support.apple.com/HT205213http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://www.securityfocus.com/bid/76764http://www.securitytracker.com/id/1033609https://support.apple.com/HT205212https://support.apple.com/HT205213
2015-09-18
Published