CVE-2019-8548Incomplete Cleanup in Apple Watchos

Severity
2.4LOWNVD
EPSS
0.1%
top 68.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 24

Description

An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clear when the device goes to sleep.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5apple/watchosunspecifiedwatchOS 5.2
NVDapple/watchos< 5.2
Appleapple/watchos5.2

🔴Vulnerability Details

1
GHSA
GHSA-4rr6-6h9f-r3pg: An issue existed where partially entered passcodes may not clear when the device went to sleep2022-05-24

📋Vendor Advisories

1
Apple
CVE-2019-8548: watchOS 5.22019-03-27