Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-3612

31
FAUCET Score

CVE-2008-3612 describes a critical vulnerability in the Networking subsystem of Apple iPod touch 2.0 through 2.0.2 and iPhone 2.0 through 2.0.2. This flaw stems from the use of predictable TCP initial sequence numbers, enabling remote attackers to spoof or hijack TCP connections. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low complexity, allowing for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, with 10 mentions, indicating considerable interest.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, <= 2.0.2CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.52%
Probability of exploitation in next 30 days
EPSS Percentile
88.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0352 is in the 80th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

applevendor investigatingvia nvd_reference
View patch

References

lists.apple.com / archives/security-announce//2008/Sep/msg00003.html
Mailing ListVendor Advisory
lists.apple.com / archives/security-announce//2008/Sep/msg00004.html
Mailing ListVendor Advisory
secunia.com / advisories/31823
Broken LinkVendor Advisory
secunia.com / advisories/31900
Broken LinkVendor Advisory
support.apple.com / kb/HT3026
Vendor Advisory
support.apple.com / kb/HT3129
Vendor Advisory
securityfocus.com / bid/31092
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
vupen.com / english/advisories/2008/2525
Broken LinkVendor Advisory
vupen.com / english/advisories/2008/2558
Broken LinkVendor Advisory