Apple iOS < 5.1.1 Multiple Vulnerabilities

critical Nessus Plugin ID 60027

Synopsis

Report iOS devices older than 5.1.1.

Description

The mobile device is running a version of iOS that is older than version 5.1.1. Version 5.1.1 contains numerous security-related fixes for the following vulnerabilities :

- Attackers can use a vulnerability in WebKit to perform cross-site scripting attacks, possibly leaking data such as cookies, user information, and passwords.
(CVE-2011-3046, CVE-2011-3056)

- A remote code execution vulnerability in WebKit could allow a malicious site to run code on the host iOS device giving the attacker access to critical data on the phone.(CVE-2012-0672)

- Vulnerabilities in Safari can allow malicious sites to spoof the address in the address bar of the browser.
This attack allows an attacker to redirect victims to a malicious site without the user's ability to notice.
(CVE-2012-0674)

Solution

Apple has released a set of patches for your iOS-based device.

See Also

https://support.apple.com/en-us/HT202475

https://www.securityfocus.com/archive/1/522612/30/210/threaded

Plugin Details

Severity: Critical

ID: 60027

File Name: apple_ios_511_check.nbin

Version: 1.107

Type: local

Published: 2/14/2012

Updated: 4/8/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2011-3046

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:apple:iphone_os

Required KB Items: mdm/dependency/unlocked

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/7/2012

Reference Information

CVE: CVE-2011-3046, CVE-2011-3056, CVE-2012-0672, CVE-2012-0674

BID: 52369, 53404, 53407, 53446