Data Deletion Flaw in AirPort Base Station by Apple
CVE-2019-8575
7.5HIGH
Key Information:
- Vendor
- Apple
- Vendor
- CVE Published:
- 27 October 2020
Summary
The vulnerability relates to inadequate data deletion in AirPort Base Station firmware, where a factory reset may leave behind residual user information. This flaw can potentially expose sensitive data to unauthorized access if not properly addressed. Apple has rectified this issue in firmware versions 7.8.1 and 7.9.1, emphasizing the importance of regular firmware updates and secure data management practices.
Affected Version(s)
AirPort Base Station Firmware Update < 7.9
AirPort Base Station Firmware Update < 7.8
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved