CVE-2019-8799Insecure Storage of Sensitive Information in Apple IOS AND Ipados

Severity
2.4LOWNVD
EPSS
0.1%
top 78.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages13 packages

CVEListV5apple/tvosunspecified13
NVDapple/tvos< 13.0
CVEListV5apple/macosunspecified10.15
NVDapple/ipados< 13.1

🔴Vulnerability Details

1
GHSA
GHSA-mgpg-rp6c-97r2: This issue was resolved by replacing device names with a random identifier2022-05-24

📋Vendor Advisories

4
Apple
CVE-2019-8799: macOS Catalina 10.152019-10-07
Apple
CVE-2019-8799: iOS 13.1 and iPadOS 13.12019-09-24
Apple
CVE-2019-8799: tvOS 132019-09-24
Apple
CVE-2019-8799: watchOS 62019-09-19
CVE-2019-8799 — Apple IOS AND Ipados vulnerability | cvebase