SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-8799

An attacker in physical proximity may be able to passively observe device names in AWDL communications.

LOW 2.4EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.

CVSS 3.1
2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Affected
apple/ipados · apple/iphone os · apple/mac os x · apple/tvos · apple/watchos
Source
product-security@apple.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.