6.8

CVE-2019-8900

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Securerom Version -
   Apple ≫ A10 Fusion Version -
   Apple ≫ A10x Fusion Version -
   Apple ≫ A11 Bionic Version -
   Apple ≫ A5 Version -
   Apple ≫ A5x Version -
   Apple ≫ A6 Version -
   Apple ≫ A6x Version -
   Apple ≫ A7 Version -
   Apple ≫ A8 Version -
   Apple ≫ A8x Version -
   Apple ≫ A9 Version -
   Apple ≫ A9x Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 68.78% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://www.kb.cert.org/vuls/id/941987
Third Party Advisory