Data Deletion Flaw in AirPort Base Station by Apple
CVE-2019-8575

7.5HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
27 October 2020

Summary

The vulnerability relates to inadequate data deletion in AirPort Base Station firmware, where a factory reset may leave behind residual user information. This flaw can potentially expose sensitive data to unauthorized access if not properly addressed. Apple has rectified this issue in firmware versions 7.8.1 and 7.9.1, emphasizing the importance of regular firmware updates and secure data management practices.

Affected Version(s)

AirPort Base Station Firmware Update < 7.9

AirPort Base Station Firmware Update < 7.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.