CVE-2009-2794
Summary
| CVE | CVE-2009-2794 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-10 21:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | 2.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.2 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.2 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.2.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.2.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 3.0 | All | All | All |
| Operating System | Apple | Iphone Os | 3.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 3.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iPhone / iPod touch Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| About the security content of iPhone OS 3.1 and iPhone OS 3.1.1 for iPod touch | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| APPLE-SA-2009-09-09-1 iPhone OS 3.1 and iPhone OS 3.1.1 for iPod touch | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.