CVE-2019-8575
published 2020-10-27CVE-2019-8575: The issue was addressed with improved data deletion. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.21%
64.9th percentile
The issue was addressed with improved data deletion. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A base station factory reset may not delete all user information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | airport_base_station_firmware | < 7.8.1 | 7.8.1 |
| apple | airport_base_station_firmware_update | — | — |
| apple | airport_base_station_firmware_update | >= unspecified < 7.9 | 7.9 |
| apple | airport_base_station_firmware_update | >= unspecified < 7.8 | 7.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63q4-jcgf-q39h: The issue was addressed with improved data deletion
ghsa_unreviewed·2022-05-24
CVE-2019-8575 [HIGH] GHSA-63q4-jcgf-q39h: The issue was addressed with improved data deletion
The issue was addressed with improved data deletion. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A base station factory reset may not delete all user information.
Apple
CVE-2019-8575: AirPort Base Station Firmware Update 7.8.1
vendor_apple·2019-06-20·CVSS 7.5
CVE-2019-8575 [HIGH] CVE-2019-8575: AirPort Base Station Firmware Update 7.8.1
Apple Security Update: About the security content of AirPort Base Station Firmware Update 7.8.1
Product: AirPort Base Station Firmware Update
Version: 7.8.1
CVE: CVE-2019-8575
Component: AirPort Base Station Firmware
Impact: A base station factory reset may not delete all user information
Description: The issue was addressed with improved data deletion.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Insufficient or Incomplete Data Removal within Hardware Component
mitre_cwe·CVSS 7.5
[HIGH] CWE-1301 Insufficient or Incomplete Data Removal within Hardware Component
CWE-1301: Insufficient or Incomplete Data Removal within Hardware Component
The product's data removal process does not completely delete all data and potentially sensitive information within hardware components.
Physical properties of hardware devices, such as remanence of magnetic media, residual charge of ROMs/RAMs, or screen burn-in may still retain sensitive data after a data removal process has taken place and power is removed. Recovering data after erasure or overwriting is possible due to a phenomenon called data remanence. For example, if the same value is written repeatedly to a memory location, the corresponding memory cells can become physically altered to a degree such that even after the original data is erased that data can still be recovered through physical characterizat
CWE
Remanent Data Readable after Memory Erase
mitre_cwe
CWE-1330 Remanent Data Readable after Memory Erase
CWE-1330: Remanent Data Readable after Memory Erase
Confidential information stored in memory circuits is readable or recoverable after being cleared or erased.
Data remanence occurs when stored, memory content is not fully lost after a memory-clear or -erase operation. Confidential memory contents can still be readable through data remanence in the hardware. Data remanence can occur because of performance optimization or memory organization during 'clear' or 'erase' operations, like a design that allows the memory-organization metadata (e.g., file pointers) to be erased without erasing the actual memory content. To protect against this weakness, memory devices will often support different commands for optimized memory erase and explicit secure erase. Data remanence can also happen becau
2020-10-27
Published