CVE-2020-9978
published 2021-04-02CVE-2020-9978: This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update…
PriorityP419medium4.5CVSS 3.1
AVAACLPRHUINSUCNIHAN
EPSS
0.52%
40.7th percentile
This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attacker in a privileged network position may be able to unexpectedly alter application state.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 14.0 | 14.0 |
| apple | ipados | < 14.0 | 14.0 |
| apple | iphone_os | < 14.0 | 14.0 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.1.0 | 11.1.0 |
| apple | macos | >= unspecified < 11.0 | 11.0 |
| apple | macos | >= unspecified < 11.1 | 11.1 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 14.0 | 14.0 |
| apple | watchos | < 7.0 | 7.0 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 7.0 | 7.0 |
CVSS provenance
nvdv3.14.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5hfq-49hj-vmf5: This issue was addressed with improved setting propagation
ghsa_unreviewed·2022-05-24
CVE-2020-9978 [MEDIUM] GHSA-5hfq-49hj-vmf5: This issue was addressed with improved setting propagation
This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attacker in a privileged network position may be able to unexpectedly alter application state.
Apple
CVE-2020-9978: tvOS 14.0
vendor_apple·2020-09-16·CVSS 4.5
CVE-2020-9978 [MEDIUM] CVE-2020-9978: tvOS 14.0
Apple Security Update: About the security content of tvOS 14.0
Product: tvOS
Version: 14.0
CVE: CVE-2020-9978
Component: HomeKit
Impact: An attacker in a privileged network position may be able to unexpectedly alter application state
Description: This issue was addressed with improved setting propagation.
Apple
CVE-2020-9978: watchOS 7.0
vendor_apple·2020-09-16·CVSS 4.5
CVE-2020-9978 [MEDIUM] CVE-2020-9978: watchOS 7.0
Apple Security Update: About the security content of watchOS 7.0
Product: watchOS
Version: 7.0
CVE: CVE-2020-9978
Component: HomeKit
Impact: An attacker in a privileged network position may be able to unexpectedly alter application state
Description: This issue was addressed with improved setting propagation.
Suricata
ET WEB_CLIENT Attempted RCE in Wordpress Social Warfare Plugin Inbound (CVE-2019-9978)
suricata·2019-05-03·CVSS 6.1
CVE-2019-9978 [MEDIUM] ET WEB_CLIENT Attempted RCE in Wordpress Social Warfare Plugin Inbound (CVE-2019-9978)
ET WEB_CLIENT Attempted RCE in Wordpress Social Warfare Plugin Inbound (CVE-2019-9978)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_CLIENT Attempted RCE in Wordpress Social Warfare Plugin Inbound (CVE-2019-9978)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"wp-admin/admin-post.php?swp_debug=load_options&swp_url="; fast_pattern; pcre:"/^https?:\/\//R"; reference:url,www.exploit-db.com/exploits/46794; classtype:attempted-admin; sid:2027315; rev:3; metadata:affected_product Wordpress_Plugins, created_at 2019_05_03, cve CVE_2019_9978, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2020_08_28;)
Nuclei
rConfig <=3.9.4 - SQL Injection
nuclei·CVSS 9.8
CVE-2020-10549 [CRITICAL] rConfig <=3.9.4 - SQL Injection
rConfig 3.9.4 or apply the provided patch to mitigate the SQL Injection vulnerability.
reference:
- https://github.com/theguly/exploits/blob/master/CVE-2020-10549.py
- https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/
- https://nvd.nist.gov/vuln/detail/CVE-2020-10549
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Elsfa7-110/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2020-10549
cwe-id: CWE-89
epss-score: 0.92992
epss-percentile: 0.9978
cpe: cpe:2.3:a:rconfig:rconfig:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: rconfig
product: rconfig
shodan-query: http.title:"rconfig"
fofa-query: title="rconfig"
google-query: intitle:"rconfig"
tags: cve,cve2020,rconfig,sqli,vuln
No writeups or analysis indexed.
https://support.apple.com/en-us/HT211843https://support.apple.com/en-us/HT211844https://support.apple.com/en-us/HT211850https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT212011https://support.apple.com/en-us/HT211843https://support.apple.com/en-us/HT211844https://support.apple.com/en-us/HT211850https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT212011
2021-04-02
Published