VDB
CVE-2008-3612
CVE-2008-3612
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
EPSS 3.52% · 88.1th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.52%
88.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | iphone_os | 2.0.0 |
Timeline
- Sep 10, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- ADV-2008-2525 vdb
- http://support.apple.com/kb/HT3129 url
- APPLE-SA-2008-09-12 vendor-advisory
- 31900 third-party-advisory
- APPLE-SA-2008-09-09 vendor-advisory
- 1020848 vdb
- http://support.apple.com/kb/HT3026 url
- 31823 third-party-advisory
- ADV-2008-2558 vdb
- 31092 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-3612 advisory