SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21301

In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it.

MEDIUM 4.3EPSS 1.02%

Does this matter?

Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.

Description

Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.02% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
wire/wire
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.