CVE-2019-8704Improper Authentication in Apple Tvos

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 85.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 24

Description

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5apple/tvosunspecifiedtvOS 13
NVDapple/tvos< 13
Appleapple/tvos13
NVDapple/iphone_os< 13.0
Appleapple/ios13

🔴Vulnerability Details

1
GHSA
GHSA-3wv5-4298-pwwf: An authentication issue was addressed with improved state management2022-05-24

📋Vendor Advisories

2
Apple
CVE-2019-8704: tvOS 132019-09-24
Apple
CVE-2019-8704: iOS 132019-09-19
CVE-2019-8704 — Improper Authentication in Apple Tvos | cvebase