CVE Vulnerabilities

CVE-2007-3754

Improper Authentication

Published: Sep 27, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
IphoneApple1.0 (including)1.0 (including)
Iphone_osApple1.0.1 (including)1.0.1 (including)
Iphone_osApple1.0.2 (including)1.0.2 (including)

Potential Mitigations

References