CVE-2015-1109: Infoleak
Published Apr 10, 2015
·Updated
NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.
Affected Software
1 affected component
apple iPhone OS<=8.2
Event History
Apr 10, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1109?
CVE-2015-1109 is considered a medium severity vulnerability.
2
How do I fix CVE-2015-1109?
To fix CVE-2015-1109, update your Apple iOS to version 8.3 or later.
3
What kind of information is exposed by CVE-2015-1109?
CVE-2015-1109 exposes sensitive VPN credentials stored in configuration logs.
4
Who is affected by CVE-2015-1109?
CVE-2015-1109 affects users of Apple iOS versions prior to 8.3.
5
What is the attack vector for CVE-2015-1109?
The attack vector for CVE-2015-1109 involves a physical proximity attack to access log files.