CVE-2020-9934
בינונית 5.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple iOS, iPadOS, and macOS Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-30/7/2026
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: mac os x
קישורים
- https://support.apple.com/HT211288 Release NotesVendor Advisory
- https://support.apple.com/HT211289 Release NotesVendor Advisory
- https://support.apple.com/HT211288 Release NotesVendor Advisory
- https://support.apple.com/HT211289 Release NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource