CVE Vulnerabilities

CVE-2020-9868

Improper Certificate Validation

Published: Oct 22, 2020 | Modified: Jan 09, 2023
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an administrator added certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 13.6 (excluding)
Iphone_os Apple * 13.6 (excluding)
Mac_os_x Apple * 10.15.6 (excluding)
Tvos Apple * 13.4.8 (excluding)
Watchos Apple * 6.2.8 (excluding)

Potential Mitigations

References