CVE-2008-3612

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
11/09/2008
Last modified:
09/04/2025

Description

The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.2 (including)