cbcvebase.
CVE-2020-9991
published 2020-12-08

CVE-2020-9991: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21…

PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.79%
84.8th percentile
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.217.21
appleicloud>= 11.0 < 11.411.4
appleicloud_for_windows
appleicloud_for_windows
appleicloud_for_windows>= unspecified < 7.217.21
appleios_and_ipados>= unspecified < 14.014.0
appleipados< 14.014.0
appleiphone_os< 14.014.0
applemac_os_x< 11.0.111.0.1
applemacos>= unspecified < 11.011.0
appletvos< 14.014.0
appletvos
appletvos>= unspecified < 14.014.0
applewatchos< 7.07.0
applewatchos
applewatchos>= unspecified < 7.07.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.