CVE-2020-9770Inadequate Encryption Strength in Apple Ipados

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 38.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 24

Description

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDapple/ipados< 13.4
CVEListV5apple/iosunspecifiediOS 13.4 and iPadOS 13.4
NVDapple/iphone_os< 13.4

🔴Vulnerability Details

3
GHSA
GHSA-f9h7-x4m7-p8mw: A logic issue was addressed with improved state management2022-05-24
CVEList
CVE-2020-9770: A logic issue was addressed with improved state management2020-04-01
OSV
CVE-2020-9770: A logic issue was addressed with improved state management2020-04-01

📋Vendor Advisories

1
Red Hat
bluez: BLESA bluetooth attack2020-09-15

💬Community

2
Bugzilla
CVE-2020-9770 bluez: BLESA bluetooth attack [fedora-all]2020-09-24
Bugzilla
CVE-2020-9770 bluez: BLESA bluetooth attack2020-09-17
CVE-2020-9770 — Inadequate Encryption Strength in Apple | cvebase