CVE-2010-0038
iPhone OS 1.0-3.1.2 - Unauthenticated Arbitrary Data Access via USB Control Message
Title source: llmDescription
Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/62128
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38040
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4013
Scores
EPSS
0.0036
EPSS Percentile
29.0%
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-399
Status
published
Products (22)
apple/iphone_os
1.0
apple/iphone_os
1.0.0
apple/iphone_os
1.0.1 (2 CPE variants)
apple/iphone_os
1.0.2 (2 CPE variants)
apple/iphone_os
1.1
apple/iphone_os
1.1.0 (3 CPE variants)
apple/iphone_os
1.1.1 (2 CPE variants)
apple/iphone_os
1.1.2 (3 CPE variants)
apple/iphone_os
1.1.3 (3 CPE variants)
apple/iphone_os
1.1.4 (3 CPE variants)
... and 12 more
Published
Feb 03, 2010
Tracked Since
Feb 18, 2026