The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://support.apple.com/kb/HT3639 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51212 | vdb entry |
http://www.vupen.com/english/advisories/2009/1621 | vdb entry vendor advisory |
http://osvdb.org/55239 | vdb entry |
http://www.securityfocus.com/bid/35414 | vdb entry |
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html | vendor advisory |
http://www.securityfocus.com/bid/35436 | vdb entry |