PT-2020-17734 · Apple · Ios+2
Sebastian Bicchi
+1
·
Published
2020-02-27
·
Updated
2021-07-21
·
CVE-2020-3841
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 13.3.1
iPadOS versions prior to 13.3.1
Safari versions prior to 13.0.5
Description
A local user may unknowingly send a password unencrypted over the network due to inadequate UI handling.
Recommendations
For iOS versions prior to 13.3.1, update to iOS 13.3.1 or later.
For iPadOS versions prior to 13.3.1, update to iPadOS 13.3.1 or later.
For Safari versions prior to 13.0.5, update to Safari 13.0.5 or later.
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safari
Ios
Ipados