CVE-2008-4228

iPhone OS 1.0-2.1 - Unauthenticated Arbitrary Phone Call via Emergency Call Feature

Title source: llm
STIX 2.1

Description

The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021271
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3232
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3318
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32394
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50025
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32756

Scores

EPSS 0.0036
EPSS Percentile 28.2%

Details

CWE
CWE-264
Status published
Products (13)
apple/iphone_os 1.0
apple/iphone_os 1.0.1
apple/iphone_os 1.0.2
apple/iphone_os 1.1
apple/iphone_os 1.1.1
apple/iphone_os 1.1.2
apple/iphone_os 1.1.3
apple/iphone_os 1.1.4
apple/iphone_os 1.1.5
apple/iphone_os 2.0
... and 3 more
Published Nov 25, 2008
Tracked Since Feb 18, 2026