CVE-2020-9946Improper Locking in Apple Watchos

CWE-667Improper Locking4 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 82.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen lock may not engage after the specified time period.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages5 packages

NVDapple/ipados< 14.0
CVEListV5apple/watchosunspecifiedwatchOS 7.0
NVDapple/watchos< 7.0
CVEListV5apple/iosunspecifiediOS 14.0 and iPadOS 14.0
NVDapple/iphone_os< 14.0

🔴Vulnerability Details

2
GHSA
GHSA-f266-qpmf-vxqx: This issue was addressed with improved checks2022-05-24
CVEList
CVE-2020-9946: This issue was addressed with improved checks2020-10-16

📋Vendor Advisories

1
Apple
CVE-2020-9946: watchOS 7.02020-09-16
CVE-2020-9946 — Improper Locking in Apple Watchos | cvebase