4.3
CVSSv2

CVE-2015-5824

Published: 18/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 4.9 | Exploitability Score: 5.5
VMScore: 383
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The NSURL implementation in the CFNetwork SSL component in Apple iOS prior to 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

apple watchos 1.0

apple mac os x

apple iphone os