« Volver al listado

CVE-2008-1589

Estado: ModificadaMedia (4.3)—

Safari en Apple iPhone anterior a 2.0 e iPod touch anterior a 2.0 no interpreta correctamente que se pulse en un botón del menú como la confirmación de un usuario al visitar un sitio Web con un certificado (1)autofirmado o (2) no válido; esto facilita a atacantes remotos falsificar los sitios Web.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1589",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-14T18:41:00.000",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN88676089/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000039.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31074",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30186",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2094/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43734",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN88676089/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000039.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31074",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30186",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2094/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43734",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites."
    },
    {
      "lang": "es",
      "value": "Safari en Apple iPhone anterior a 2.0 e iPod touch anterior a 2.0 no interpreta correctamente que se pulse en un botón del menú como la confirmación de un usuario al visitar un sitio Web con un certificado (1)autofirmado o (2) no válido; esto facilita a atacantes remotos falsificar los sitios Web."
    }
  ],
  "lastModified": "2026-06-16T22:52:02.217",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:apple:iphone:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5F382364-1B45-4C62-AB29-A20512AA77D9"
            },
            {
              "criteria": "cpe:2.3:h:apple:iphone:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D05600E6-6BC5-43C4-93E2-72585A3453B5"
            },
            {
              "criteria": "cpe:2.3:h:apple:iphone:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6430229D-ACD4-46AE-A6B5-95D3CC1AF514"
            },
            {
              "criteria": "cpe:2.3:h:apple:iphone:1.02:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CA40173B-5F79-400E-9540-7E0BF7A78E35"
            },
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:1.1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A22F1F9E-F5B0-4AB4-8CE9-50C540AE1AE9"
            },
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BE66FF90-ED80-4184-820B-88F1BA250F71"
            },
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "05097B1E-425A-4EF5-8D44-FFEC22994B6A"
            },
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7A0EBA08-CE54-4AE3-9AED-514392372B7D"
            },
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4E969C4E-45A5-4767-9959-A1AD2DE4E1C2"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0C5B94E7-2C24-4913-B65E-8D8A0DE2B80B"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E28FB0CB-D636-4F85-B5F7-70EC30053925"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "27319629-171F-42AA-A95F-2D71F78097D0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4F7AEFAB-7BB0-40D8-8BA5-71B374EB69DB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE370CAA-04B3-434E-BD5B-1D87DE596C10"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}