{"api_version":"1","generated_at":"2026-07-23T10:16:38+00:00","cve":"CVE-2015-3756","urls":{"html":"https://cve.report/CVE-2015-3756","api":"https://cve.report/api/cve/CVE-2015-3756.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3756","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3756"},"summary":{"title":"CVE-2015-3756","description":"The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.","state":"PUBLISHED","assigner":"apple","published_at":"2015-08-16 23:59:29","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-254","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id/1033275","name":"http://www.securitytracker.com/id/1033275","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, and Deny Service and Let Apps Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT205030","name":"https://support.apple.com/kb/HT205030","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 8.4.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2015-08-13-3 iOS 8.4.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76337","name":"http://www.securityfocus.com/bid/76337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS APPLE-SA-2015-08-13-3 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3756","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3756","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3756","vulnerable":"1","versionEndIncluding":"8.4","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:56:14.915Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT205030"},{"name":"1033275","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033275"},{"name":"76337","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76337"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-22T18:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT205030"},{"name":"1033275","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033275"},{"name":"76337","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76337"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2015-3756","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://support.apple.com/kb/HT205030","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT205030"},{"name":"1033275","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033275"},{"name":"76337","refsource":"BID","url":"http://www.securityfocus.com/bid/76337"},{"name":"APPLE-SA-2015-08-13-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2015-3756","datePublished":"2015-08-16T23:00:00.000Z","dateReserved":"2015-05-07T00:00:00.000Z","dateUpdated":"2024-08-06T05:56:14.915Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-16 23:59:29","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-254","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"8.4","matchCriteriaId":"0D52ECBD-7375-4FC9-BE05-2354EEA1332F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3756","Ordinal":"1","Title":"CVE-2015-3756","CVE":"CVE-2015-3756","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3756","Ordinal":"1","NoteData":"The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.","Type":"Description","Title":"CVE-2015-3756"},{"CveYear":"2015","CveId":"3756","Ordinal":"2","NoteData":"2015-08-16","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3756","Ordinal":"3","NoteData":"2016-12-22","Type":"Other","Title":"Modified"}]}}}