CVE-2015-1103 describes a vulnerability in Apple iOS, OS X, and tvOS kernels where crafted ICMP_REDIRECT messages can lead to routing changes. This flaw allows remote attackers to cause a denial of service (network outage) or gain access to sensitive packet content. With a CVSS score of 7.5, it is considered highly severe, requiring no authentication and having low attack complexity, with potential impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating limited public attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 7.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
<= 10.10.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.