First published: Thu Sep 27 2007(Updated: )
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | =1.0.2 | |
Apple iPhone | =1.0 | |
iStyle @cosme iPhone OS | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3754 is considered a critical vulnerability due to its potential for credential theft via man-in-the-middle attacks.
To mitigate CVE-2007-3754, ensure you update your Apple iPhone to the latest version of the operating system that addresses this vulnerability.
CVE-2007-3754 affects Apple iPhone OS versions 1.0, 1.0.1, and 1.0.2.
CVE-2007-3754 exploits the lack of SSL warnings when there are changes in mail server certificates.
Using an affected iPhone without the fix poses significant risks, especially when accessing email over SSL.