CVE-2019-8796
published 2020-10-27CVE-2019-8796: A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.34%
56.8th percentile
A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iOS 12.4.3, watchOS 6.1, iOS 13.2 and iPadOS 13.2. AirDrop transfers may be unexpectedly accepted while in Everyone mode.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios_13.2_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 13.2 | 13.2 |
| apple | ipados | < 13.2 | 13.2 |
| apple | iphone_os | < 12.4.3 | 12.4.3 |
| apple | iphone_os | >= 13.0 < 13.2 | 13.2 |
| apple | mac_os_x | < 10.15.1 | 10.15.1 |
| apple | macos | >= unspecified < 10.15 | 10.15 |
| apple | macos | >= unspecified < 6.1 | 6.1 |
| apple | macos | >= unspecified < 12.4 | 12.4 |
| apple | macos_catalina_10.15.1_security_update_2019-001_and_security_update_2019-006 | — | — |
| apple | watchos | < 6.1 | 6.1 |
| apple | watchos | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Apple
CVE-2019-8796: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
vendor_apple·2019-10-29·CVSS 5.3
CVE-2019-8796 [MEDIUM] CVE-2019-8796: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
Apple Security Update: About the security content of macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
Product: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
CVE: CVE-2019-8796
Component: Accounts
Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode
Description: A logic issue was addressed with improved validation.
Apple
CVE-2019-8796: watchOS 6.1
vendor_apple·2019-10-29·CVSS 5.3
CVE-2019-8796 [MEDIUM] CVE-2019-8796: watchOS 6.1
Apple Security Update: About the security content of watchOS 6.1
Product: watchOS
Version: 6.1
CVE: CVE-2019-8796
Component: AirDrop
Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode
Description: A logic issue was addressed with improved validation.
Apple
CVE-2019-8796: iOS 13.2 and iPadOS 13.2
vendor_apple·2019-10-28·CVSS 5.3
CVE-2019-8796 [MEDIUM] CVE-2019-8796: iOS 13.2 and iPadOS 13.2
Apple Security Update: About the security content of iOS 13.2 and iPadOS 13.2
Product: iOS 13.2 and iPadOS
Version: 13.2
CVE: CVE-2019-8796
Component: AirDrop
Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode
Description: A logic issue was addressed with improved validation.
Apple
CVE-2019-8796: iOS 12.4.3
vendor_apple·2019-10-28·CVSS 5.3
CVE-2019-8796 [MEDIUM] CVE-2019-8796: iOS 12.4.3
Apple Security Update: About the security content of iOS 12.4.3
Product: iOS
Version: 12.4.3
CVE: CVE-2019-8796
Component: Accounts
Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode
Description: A logic issue was addressed with improved validation.
GHSA
GHSA-mpwc-4w8x-rmc7: A logic issue was addressed with improved validation
ghsa_unreviewed·2022-05-24
CVE-2019-8796 [MEDIUM] GHSA-mpwc-4w8x-rmc7: A logic issue was addressed with improved validation
A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iOS 12.4.3, watchOS 6.1, iOS 13.2 and iPadOS 13.2. AirDrop transfers may be unexpectedly accepted while in Everyone mode.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT210721https://support.apple.com/en-us/HT210722https://support.apple.com/en-us/HT210724https://support.apple.com/en-us/HT211134https://support.apple.com/en-us/HT210721https://support.apple.com/en-us/HT210722https://support.apple.com/en-us/HT210724https://support.apple.com/en-us/HT211134
2020-10-27
Published