CVE-2019-8901: Medium severity apple ios and ipados vulnerability
Shortcuts. This issue was addressed by verifying host keys when connecting to a previously-known SSH server.
Other sources
This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the “Run script over SSH” action.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8901.
What is the severity rating for CVE-2019-8901?
CVE-2019-8901 has a severity rating of medium (6.5).
What is the affected software?
The affected software includes Apple iOS versions up to but excluding 13.1, Apple iPadOS versions up to but excluding 13.1, Apple iPadOS 13.1, and Apple iPhone OS versions up to but excluding 13.1.
How can an attacker exploit this vulnerability?
An attacker in a privileged network position may intercept SSH traffic from the "Run script over SSH" action.
How was this vulnerability fixed?
This vulnerability was fixed in iOS 13.1 and iPadOS 13.1 by verifying host keys when connecting to a previously-known SSH server.