CVE-2015-6999 PUBLISHED CVSS 5 MEDIUM

The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate.

EPSS 0.22% · 44.5th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
0.22%
44.5th percentile

Affected Products

VendorProductVersions
n/an/an/a
appleiphone_os0

Timeline

References

Open in Interactive Console →