PT-2008-5521 · Apple · Ios+1
Published
2008-11-25
·
Updated
2022-08-09
·
CVE-2008-4228
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Apple iPhone OS versions 1.0 through 2.1
Apple iPhone OS for iPod touch versions 1.1 through 2.1
Description:
The issue allows physically proximate attackers to make a phone call to an arbitrary number by leveraging the emergency-call ability of locked devices.
Recommendations:
For Apple iPhone OS versions 1.0 through 2.1, consider disabling the emergency-call feature when the device is locked to prevent unauthorized access.
For Apple iPhone OS for iPod touch versions 1.1 through 2.1, restrict the ability to make calls when the device is locked to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ios
Iphone Os For Ipod Touch