CVE-2020-9819

MEDIUM(4.3)KEV

Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Description

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.

KEV Information

Vendor
Apple
Product
iOS, iPadOS, and watchOS
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4

CWEs

Affected Products

VendorProductVersion
appleipados< 13.5
appleiphone os< 12.4.7; >= 13.0, < 13.5
applewatchos< 5.3.7; >= 6.0.0, < 6.2.5

Multiple CVSS Assessments

Source: [email protected](Primary)
4.3
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
4.3
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

References

CVSS Score

4.3
MEDIUM(4.3)

EPSS Score

EPSS Score2.18%
EPSS Percentile80.4%

Dates

PublishedJune 9, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.