CVE-2019-8803

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2019
Last modified:
26/12/2019

Description

An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 13.2 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 13.2 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.15.1 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 13.2 (excluding)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 6.1 (excluding)