ID

VAR-202010-1499


CVE

CVE-2020-9992


TITLE

plural Apple Product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2020-009677

DESCRIPTION

This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session over the network. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. There are security holes in Apple iOS. Installation note: Xcode 12.0 may be obtained from: https://developer.apple.com/xcode/downloads/ To check that the Xcode has been updated: * Select Xcode in the menu bar * Select About Xcode * The version after applying this update will be "Xcode 12.0". -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 iOS 14.0 and iPadOS 14.0 are now available and address the following: AppleAVD Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: An application may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2020-9958: Mohamed Ghannam (@_simo36) Assets Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: An attacker may be able to misuse a trust relationship to download malicious content Description: A trust issue was addressed by removing a legacy API. CVE-2020-9979: CodeColorist of Ant-Financial LightYear Labs Icons Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: A malicious application may be able to identify what other applications a user has installed Description: The issue was addressed with improved handling of icon caches. CVE-2020-9992: Dany Lisiansky (@DanyL931), Nikias Bassen IOSurfaceAccelerator Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: A local user may be able to read kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2020-9964: Mohamed Ghannam (@_simo36), Tommy Muir (@Muirey03) Keyboard Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: A malicious application may be able to leak sensitive user information Description: A logic issue was addressed with improved state management. CVE-2020-9976: Rias A. Sherzad of JAIDE GmbH in Hamburg, Germany Model I/O Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2020-9973: Aleksandar Nikolic of Cisco Talos Phone Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: The screen lock may not engage after the specified time period Description: This issue was addressed with improved checks. CVE-2020-9946: Daniel Larsson of iolight AB Sandbox Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: A malicious application may be able to access restricted files Description: A logic issue was addressed with improved restrictions. CVE-2020-9968: Adam Chester(@xpn) of TrustedSec Siri Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: A person with physical access to an iOS device may be able to view notification contents from the lockscreen Description: A lock screen issue allowed access to messages on a locked device. This issue was addressed with improved state management. CVE-2020-9959: an anonymous researcher, an anonymous researcher, an anonymous researcher, an anonymous researcher, an anonymous researcher, Andrew Goldberg The University of Texas at Austin, McCombs School of Business, Meli̇h Kerem Güneş of Li̇v College, Sinan Gulguler WebKit Available for: iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later Impact: Processing maliciously crafted web content may lead to a cross site scripting attack Description: An input validation issue was addressed with improved input validation. CVE-2020-9952: Ryan Pickren (ryanpickren.com) Additional recognition App Store We would like to acknowledge Giyas Umarov of Holmdel High School for their assistance. Bluetooth We would like to acknowledge Andy Davis of NCC Group and Dennis Heinze (@ttdennis) of TU Darmstadt, Secure Mobile Networking Lab for their assistance. CallKit We would like to acknowledge Federico Zanetello for their assistance. CarPlay We would like to acknowledge an anonymous researcher for their assistance. Core Location We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for their assistance. debugserver We would like to acknowledge Linus Henze (pinauten.de) for their assistance. iAP We would like to acknowledge Andy Davis of NCC Group for their assistance. iBoot We would like to acknowledge Brandon Azad of Google Project Zero for their assistance. Kernel We would like to acknowledge Brandon Azad of Google Project Zero for their assistance. libarchive We would like to acknowledge Dzmitry Plotnikau and an anonymous researcher for their assistance. Location Framework We would like to acknowledge an anonymous researcher for their assistance. Maps We would like to acknowledge Matthew Dolan of Amazon Alexa for their assistance. NetworkExtension We would like to acknowledge Thijs Alkemade of Computest and ‘Qubo Song’ of ‘Symantec, a division of Broadcom’ for their assistance. Phone Keypad We would like to acknowledge an anonymous researcher for their assistance. Status Bar We would like to acknowledge Abdul M. Majumder, Abdullah Fasihallah of Taif university, Adwait Vikas Bhide, Frederik Schmid, Nikita, and an anonymous researcher for their assistance. Telephony We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for their assistance. UIKit We would like to acknowledge Borja Marcos of Sarenet, Simon de Vegt, and Talal Haj Bakry (@hajbakri) and Tommy Mysk (@tommymysk) of Mysk Inc for their assistance. Web App We would like to acknowledge Augusto Alvarez of Outcourse Limited for their assistance. Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "iOS 14.0 and iPadOS 14.0". -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl9igm4ACgkQZcsbuWJ6 jjDK/hAAndL9caBfy/uHMnz9jhpDNrJuDai5gTZeAhUSwRalVppYwTEMpcSrx7u6 O7R0uLcvd1v9AiTGpF2zcERNlQbd7L1GaErPBaWnPbXSzLoUDkCNxuw5S+EEGuF5 nOxvh+qaS1ISny6teXpW6VLvLqV6n3BuNHUAbyP1JuF/EB7V9R1MD8zOUM7jsn6t Lwyz++s1nQbwt2jH1OKZa0pP2cSjVJjlKi8iDnFnMUjaSn8LCsgNXTsvipX8rA7r aeUxlPkIA2bwM5/0CFoPWpoPjNKXxoADjryJOat0GjPp/dSewrXncE/aKvrJGcJ7 Hwg4Q2Ep8a6NKL1QZ3ST64kf28UTA06xcypzinIpJVqtLj8LOvRDUGak3h+xETHB E4evSHlNfDzKrzu7kArguneeh4IwSpN1kSc4kt2rGpAQ0ch0bT34AzbNDpoUidm1 oPU3WVcEeBD9PYKGAWMiBcm3X6B0wHsAYDLCgkqnxrbDgz7NlsmVIl3dvrVbLrl1 jxaVaofaqANk+uTzoB1QArZRowf5GzW17htRijPazna1qYHo6jp/fzrGbdoMDuhb 80JpytEZrrVvscbth4bTeex52ibn1XFM9kqAX/Mfxaob2zBKt0fF6v3utFRKmx9g fhqMR3CPf7QVG8mlYMQ57OT7iuQ4lYkFw9qGgPI4SGWiMWWVtUU= =7kDq -----END PGP SIGNATURE-----

Trust: 1.98

sources: NVD: CVE-2020-9992 // JVNDB: JVNDB-2020-009677 // VULHUB: VHN-188117 // VULMON: CVE-2020-9992 // PACKETSTORM: 159229 // PACKETSTORM: 159223

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:ltversion:14.0

Trust: 1.0

vendor:applemodel:xcodescope:ltversion:12.0

Trust: 1.0

vendor:applemodel:ipadosscope:ltversion:14.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.15.4 以降

Trust: 0.8

vendor:applemodel:iosscope:eqversion:14.0 未満 (ipod touch 第 7 世代)

Trust: 0.8

vendor:applemodel:ipadosscope:eqversion:14.0 未満 (ipad air 2 以降)

Trust: 0.8

vendor:applemodel:iosscope:eqversion:14.0 未満 (iphone 6s 以降)

Trust: 0.8

vendor:applemodel:ipadosscope:eqversion:14.0 未満 (ipad mini 4 以降)

Trust: 0.8

sources: JVNDB: JVNDB-2020-009677 // NVD: CVE-2020-9992

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9992
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-009677
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202009-1037
value: HIGH

Trust: 0.6

VULHUB: VHN-188117
value: HIGH

Trust: 0.1

VULMON: CVE-2020-9992
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2020-9992
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-009677
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-188117
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-9992
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009677
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-188117 // VULMON: CVE-2020-9992 // JVNDB: JVNDB-2020-009677 // CNNVD: CNNVD-202009-1037 // NVD: CVE-2020-9992

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2020-9992

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202009-1037

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202009-1037

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009677

PATCH

title:HT211848url:https://support.apple.com/en-us/HT211848

Trust: 0.8

title:HT211850url:https://support.apple.com/en-us/HT211850

Trust: 0.8

title:HT211850url:https://support.apple.com/ja-jp/HT211850

Trust: 0.8

title:HT211848url:https://support.apple.com/ja-jp/HT211848

Trust: 0.8

title:Apple iOS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=130573

Trust: 0.6

title:pentesturl:https://github.com/iamrajivd/pentest

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/Micle5858/PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/bjknbrrr/PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/Saidul-M-Khan/PENTESTING-BIBLE

Trust: 0.1

title:ALL-PENTESTING-BIBLEurl:https://github.com/Mathankumar2701/ALL-PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/NetW0rK1le3r/PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/nitishbadole/PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/OCEANOFANYTHING/PENTESTING-BIBLE

Trust: 0.1

title: - url:https://github.com/dli408097/pentesting-bible

Trust: 0.1

title: - url:https://github.com/readloud/Pentesting-Bible

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/phant0n/PENTESTING-BIBLE

Trust: 0.1

title:PENTESTING-BIBLEurl:https://github.com/MedoX71T/PENTESTING-BIBLE

Trust: 0.1

title: - url:https://github.com/hacker-insider/Hacking

Trust: 0.1

title:macOS-iOS-system-securityurl:https://github.com/houjingyi233/macOS-iOS-system-security

Trust: 0.1

title:sec-daily-2020url:https://github.com/alphaSeclab/sec-daily-2020

Trust: 0.1

sources: VULMON: CVE-2020-9992 // JVNDB: JVNDB-2020-009677 // CNNVD: CNNVD-202009-1037

EXTERNAL IDS

db:NVDid:CVE-2020-9992

Trust: 2.8

db:PACKETSTORMid:159229

Trust: 0.8

db:JVNid:JVNVU92546061

Trust: 0.8

db:JVNDBid:JVNDB-2020-009677

Trust: 0.8

db:AUSCERTid:ESB-2020.3187

Trust: 0.6

db:AUSCERTid:ESB-2020.3181.2

Trust: 0.6

db:NSFOCUSid:50121

Trust: 0.6

db:CNNVDid:CNNVD-202009-1037

Trust: 0.6

db:PACKETSTORMid:159223

Trust: 0.2

db:CNVDid:CNVD-2020-59479

Trust: 0.1

db:VULHUBid:VHN-188117

Trust: 0.1

db:VULMONid:CVE-2020-9992

Trust: 0.1

sources: VULHUB: VHN-188117 // VULMON: CVE-2020-9992 // JVNDB: JVNDB-2020-009677 // PACKETSTORM: 159229 // PACKETSTORM: 159223 // CNNVD: CNNVD-202009-1037 // NVD: CVE-2020-9992

REFERENCES

url:http://seclists.org/fulldisclosure/2020/nov/20

Trust: 1.7

url:https://support.apple.com/ht211848

Trust: 1.7

url:https://support.apple.com/ht211850

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-9992

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9992

Trust: 0.8

url:http://jvn.jp/vu/jvnvu92546061/index.html

Trust: 0.8

url:https://support.apple.com/kb/ht211850

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-ios-multiple-vulnerabilities-33346

Trust: 0.6

url:https://support.apple.com/en-us/ht211848

Trust: 0.6

url:https://packetstormsecurity.com/files/159229/apple-security-advisory-2020-09-16-5.html

Trust: 0.6

url:http://www.nsfocus.net/vulndb/50121

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.3181.2/

Trust: 0.6

url:https://support.apple.com/en-us/ht211850

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.3187/

Trust: 0.6

url:https://developer.apple.com/xcode/downloads/

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9976

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9964

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9946

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9773

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9968

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9959

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9973

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9952

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9958

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9979

Trust: 0.1

sources: VULHUB: VHN-188117 // JVNDB: JVNDB-2020-009677 // PACKETSTORM: 159229 // PACKETSTORM: 159223 // CNNVD: CNNVD-202009-1037 // NVD: CVE-2020-9992

CREDITS

Apple

Trust: 0.8

sources: PACKETSTORM: 159229 // PACKETSTORM: 159223 // CNNVD: CNNVD-202009-1037

SOURCES

db:VULHUBid:VHN-188117
db:VULMONid:CVE-2020-9992
db:JVNDBid:JVNDB-2020-009677
db:PACKETSTORMid:159229
db:PACKETSTORMid:159223
db:CNNVDid:CNNVD-202009-1037
db:NVDid:CVE-2020-9992

LAST UPDATE DATE

2024-08-14T12:45:15.791000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-188117date:2023-01-09T00:00:00
db:VULMONid:CVE-2020-9992date:2023-01-09T00:00:00
db:JVNDBid:JVNDB-2020-009677date:2020-11-27T05:17:07
db:CNNVDid:CNNVD-202009-1037date:2021-11-03T00:00:00
db:NVDid:CVE-2020-9992date:2023-01-09T16:41:59.350

SOURCES RELEASE DATE

db:VULHUBid:VHN-188117date:2020-10-16T00:00:00
db:VULMONid:CVE-2020-9992date:2020-10-16T00:00:00
db:JVNDBid:JVNDB-2020-009677date:2020-11-27T05:17:07
db:PACKETSTORMid:159229date:2020-09-18T19:11:15
db:PACKETSTORMid:159223date:2020-09-18T17:15:27
db:CNNVDid:CNNVD-202009-1037date:2020-09-16T00:00:00
db:NVDid:CVE-2020-9992date:2020-10-16T17:15:18.433