AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2794

MEDIUM · CVSS 4.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-2794
Severity
MEDIUM
CVSS
4.6
EPSS
0.26%
Microsoft Exchange

Original NVD Description

The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.