A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an administrator added certificate.
References
Link | Resource |
---|---|
https://support.apple.com/kb/HT211288 | Vendor Advisory |
https://support.apple.com/kb/HT211289 | Vendor Advisory |
https://support.apple.com/kb/HT211290 | Vendor Advisory |
https://support.apple.com/kb/HT211291 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apple
Published: 2020-10-22T17:54:39
Updated: 2020-10-22T17:54:39
Reserved: 2020-03-02T00:00:00
Link: CVE-2020-9868
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-10-22T18:15:14.050
Modified: 2023-01-09T16:41:59.350
Link: CVE-2020-9868
JSON object: View
Redhat Information
No data.
CWE