CVE-2020-9976Sensitive Information Exposure in Apple Tvos

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 47.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0. A malicious application may be able to leak sensitive user information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5apple/tvosunspecifiedtvOS 14.0
NVDapple/tvos< 14.0
NVDapple/ipados< 14.0
CVEListV5apple/watchosunspecifiedwatchOS 7.0
NVDapple/watchos< 7.0

🔴Vulnerability Details

2
GHSA
GHSA-x4f7-hgxg-q85h: A logic issue was addressed with improved state management2022-05-24
CVEList
CVE-2020-9976: A logic issue was addressed with improved state management2020-10-16

💥Exploits & PoCs

1
Nuclei
Netsweeper <=6.4.3 - Python Code Injection

📋Vendor Advisories

2
Apple
CVE-2020-9976: watchOS 7.02020-09-16
Apple
CVE-2020-9976: tvOS 14.02020-09-16
CVE-2020-9976 — Sensitive Information Exposure in Apple | cvebase