peter bassill · operator
$ cve CVE-2008-3612 JSON

CVE-2008-3612

9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.52% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-330
On CISA KEVno
Public exploitnone known
Published2008-09-11
Last modified2026-06-16

Affected (1)

VendorProduct
appleiphone os

References

→ the Explorer  ·  watch your stack  ·  NVD