CVE-2008-3612 describes a critical vulnerability in the Networking subsystem of Apple iPod touch 2.0 through 2.0.2 and iPhone 2.0 through 2.0.2. This flaw stems from the use of predictable TCP initial sequence numbers, enabling remote attackers to spoof or hijack TCP connections. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low complexity, allowing for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, with 10 mentions, indicating considerable interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.0.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.