PT-2015-2130 · Apple · Ios
Amit Klein
·
Published
2015-09-18
·
Updated
2018-10-09
·
CVE-2015-5912
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 9
Description
The issue is related to errors in the code of the CFNetwork FTPProtocol component. It allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses. This can be exploited by a remote attacker to initiate TCP connections with nodes on the internal network using specially formed response requests.
Recommendations
For versions prior to 9, update to iOS version 9 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ios