CVE-2020-9819
MEDIUM(4.3)KEV
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Description
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| apple | ipados | < 13.5 |
| apple | iphone os | < 12.4.7; >= 13.0, < 13.5 |
| apple | watchos | < 5.3.7; >= 6.0.0, < 6.2.5 |
Multiple CVSS Assessments
Source: [email protected](Primary)
4.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
4.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
References
- https://support.apple.com/HT211168(Release Notes, Vendor Advisory)
- https://support.apple.com/HT211169(Release Notes, Vendor Advisory)
- https://support.apple.com/HT211175(Release Notes, Vendor Advisory)
- https://support.apple.com/HT211176(Release Notes, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9819(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.