Vulnerability Details CVE-2011-3427
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.6%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2011-3427
-
cpe:2.3:a:apple:apple_tv:4.0
-
cpe:2.3:a:apple:apple_tv:4.1
-
cpe:2.3:a:apple:apple_tv:4.2
-
cpe:2.3:a:apple:apple_tv:4.3
-
cpe:2.3:o:apple:iphone_os:3.0
-
cpe:2.3:o:apple:iphone_os:3.1
-
cpe:2.3:o:apple:iphone_os:3.1.2
-
cpe:2.3:o:apple:iphone_os:3.1.3
-
cpe:2.3:o:apple:iphone_os:3.2
-
cpe:2.3:o:apple:iphone_os:3.2.1
-
cpe:2.3:o:apple:iphone_os:3.2.2
-
cpe:2.3:o:apple:iphone_os:4.0
-
cpe:2.3:o:apple:iphone_os:4.0.1
-
cpe:2.3:o:apple:iphone_os:4.0.2
-
cpe:2.3:o:apple:iphone_os:4.1
-
cpe:2.3:o:apple:iphone_os:4.2.1
-
cpe:2.3:o:apple:iphone_os:4.2.5
-
cpe:2.3:o:apple:iphone_os:4.2.8
-
cpe:2.3:o:apple:iphone_os:4.3.0
-
cpe:2.3:o:apple:iphone_os:4.3.1
-
cpe:2.3:o:apple:iphone_os:4.3.2
-
cpe:2.3:o:apple:iphone_os:4.3.3
-
cpe:2.3:o:apple:iphone_os:4.3.5