First published: Tue Sep 24 2019(Updated: )
Shortcuts. This issue was addressed by verifying host keys when connecting to a previously-known SSH server.
Credit: an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <13.1 | |
Apple iPhone OS | <13.1 | |
Apple iOS | <13.1 | 13.1 |
Apple iPadOS | <13.1 | 13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2019-8901.
CVE-2019-8901 has a severity rating of medium (6.5).
The affected software includes Apple iOS versions up to but excluding 13.1, Apple iPadOS versions up to but excluding 13.1, Apple iPadOS 13.1, and Apple iPhone OS versions up to but excluding 13.1.
An attacker in a privileged network position may intercept SSH traffic from the "Run script over SSH" action.
This vulnerability was fixed in iOS 13.1 and iPadOS 13.1 by verifying host keys when connecting to a previously-known SSH server.