Vulnerability Details CVE-2015-3996
The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-3996
-
cpe:2.3:a:afnetworking_project:afnetworking:0.10.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.10.1
-
cpe:2.3:a:afnetworking_project:afnetworking:0.2.1
-
cpe:2.3:a:afnetworking_project:afnetworking:0.3.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.4.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.5.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.5.1
-
cpe:2.3:a:afnetworking_project:afnetworking:0.6.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.6.1
-
cpe:2.3:a:afnetworking_project:afnetworking:0.7.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.8.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.9.0
-
cpe:2.3:a:afnetworking_project:afnetworking:0.9.1
-
cpe:2.3:a:afnetworking_project:afnetworking:0.9.2
-
cpe:2.3:a:afnetworking_project:afnetworking:1.0
-
cpe:2.3:a:afnetworking_project:afnetworking:1.0.1
-
cpe:2.3:a:afnetworking_project:afnetworking:1.1.0
-
cpe:2.3:a:afnetworking_project:afnetworking:1.2.0
-
cpe:2.3:a:afnetworking_project:afnetworking:1.2.1
-
cpe:2.3:a:afnetworking_project:afnetworking:1.3.0
-
cpe:2.3:a:afnetworking_project:afnetworking:1.3.1
-
cpe:2.3:a:afnetworking_project:afnetworking:1.3.2
-
cpe:2.3:a:afnetworking_project:afnetworking:1.3.3
-
cpe:2.3:a:afnetworking_project:afnetworking:1.3.4
-
cpe:2.3:a:afnetworking_project:afnetworking:2.0.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.0.1
-
cpe:2.3:a:afnetworking_project:afnetworking:2.0.2
-
cpe:2.3:a:afnetworking_project:afnetworking:2.0.3
-
cpe:2.3:a:afnetworking_project:afnetworking:2.1.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.2.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.2.1
-
cpe:2.3:a:afnetworking_project:afnetworking:2.2.2
-
cpe:2.3:a:afnetworking_project:afnetworking:2.2.3
-
cpe:2.3:a:afnetworking_project:afnetworking:2.2.4
-
cpe:2.3:a:afnetworking_project:afnetworking:2.3.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.3.1
-
cpe:2.3:a:afnetworking_project:afnetworking:2.4.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.4.1
-
cpe:2.3:a:afnetworking_project:afnetworking:2.5.0
-
cpe:2.3:a:afnetworking_project:afnetworking:2.5.1
-
cpe:2.3:a:afnetworking_project:afnetworking:2.5.2