CVE-2020-9979Apple IOS AND Ipados vulnerability

3 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 69.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5apple/tvosunspecified14.0
NVDapple/tvos< 14.0
NVDapple/ipados< 14.0
CVEListV5apple/ios_and_ipadosunspecified14.0
Appleapple/tvos14.0

🔴Vulnerability Details

1
GHSA
GHSA-64f5-m6mp-5j6r: A trust issue was addressed by removing a legacy API2022-05-24

📋Vendor Advisories

1
Apple
CVE-2020-9979: tvOS 14.02020-09-16
CVE-2020-9979 — Apple IOS AND Ipados vulnerability | cvebase