V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-27950
CVE
Medium KEVConfirmedExploit available

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security …

CVSS
5.5
Medium
EPSS
0.44
p97
Published
2020-01-01
Updated
2021-11-03
Description

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

Tags · CWE
KEV
CWE-665
CAPEC-26
CAPEC-29
Affected products
Ipados < 14.2Iphone_os < 12.4.9Iphone_os 14.0–14.2Macos < 10.15.7Macos 11.0–11.0.1Watchos < 5.3.9Watchos 6.0–6.2.9Watchos 7.0–7.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2020-01-01
Published
2021-11-03
Added to KEV
2021-11-03
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.438 · p97
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2020-27950
github-poc · https://github.com/synacktiv/CVE-2020-27950
Enterprise
Affected software
ProductVendorStatus
ipados*Exploited
iphone_os*Exploited
macos*Exploited
watchos*Exploited
Source databases
CVE
Related vulnerabilities