CVE Vulnerabilities

CVE-2007-3754

Improper Authentication

Published: Sep 27, 2007 | Modified: Aug 09, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Iphone Apple 1.0 (including) 1.0 (including)
Iphone_os Apple 1.0.1 (including) 1.0.1 (including)
Iphone_os Apple 1.0.2 (including) 1.0.2 (including)

Potential Mitigations

References