First published: Fri Oct 14 2011(Updated: )
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =4.0 | |
iPhone OS | =4.3.2 | |
iPhone OS | =4.0.2 | |
iPhone OS | =4.0.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.2.8 | |
iPhone OS | =4.1 | |
iPhone OS | =3.1.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1.3 | |
iPhone OS | =4.3.1 | |
iPhone OS | =4.2.5 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.1 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =4.2.1 | |
iPhone OS | =3.0 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.3.3 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.0 | |
iPhone OS | =3.1 | |
iPhone OS | =4.0 | |
iPhone OS | =4.3.0 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3434 is classified as a medium severity vulnerability.
To mitigate CVE-2011-3434, users should upgrade to iOS version 5 or later.
CVE-2011-3434 could allow attackers to access sensitive WiFi credentials stored on vulnerable devices.
CVE-2011-3434 affects various versions of iOS up to 4.3.5.
Yes, CVE-2011-3434 can be exploited remotely via a crafted application.