CVE-2009-1679: Low severity apple iPhone OS vulnerability
The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1679?
CVE-2009-1679 has been assigned a medium severity rating due to the potential to weaken password policies on affected devices.
How do I fix CVE-2009-1679?
To mitigate CVE-2009-1679, ensure that your iPhone OS or iPod touch devices are updated to the latest firmware version available.
Which versions are affected by CVE-2009-1679?
CVE-2009-1679 affects Apple iPhone OS versions from 1.0 through 2.2.1 and Apple iPod touch versions from 1.1 through 2.2.1.
Who is impacted by CVE-2009-1679?
Users of Apple iPhone OS and iPod touch devices who install configuration profiles are potentially at risk from CVE-2009-1679.
What type of attacks can exploit CVE-2009-1679?
This vulnerability allows physically proximate attackers to bypass stronger password policies by exploiting the replacement of these policies during profile installation.