IPv4 Packet Handling Issue in Apple AirPort Base Station Products
CVE-2019-8580

7.5HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
27 October 2020

Summary

An issue has been identified in which source-routed IPv4 packets may be unexpectedly accepted by Apple AirPort Base Station products. This vulnerability arises from the default disabling of source-routed IPv4 packet acceptance, and despite this, there remains a possibility for these packets to be processed. Users are strongly advised to update to the latest firmware versions, specifically AirPort Base Station Firmware Update 7.8.1 or 7.9.1, to mitigate potential risks.

Affected Version(s)

AirPort Base Station Firmware Update < 7.9

AirPort Base Station Firmware Update < 7.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.