CVE-2020-3917: Medium severity Apple This document describes the security content of tvOS vulnerability
ActionKit. This issue was addressed with a new entitlement.
Other sources
This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to use an SSH client provided by private frameworks.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.4 - Compensating control
Address the issue by using the new entitlement introduced to fix it.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3917
- CVE-2020-3883
- CVE-2020-9768
- CVE-2020-3919
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3918
- CVE-2020-9787
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3902
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-3913
- CVE-2020-3916
- CVE-2020-3891
- CVE-2020-9770
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3890
- CVE-2020-9775
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is the vulnerability ID for this issue in ActionKit?
The vulnerability ID for this issue in ActionKit is CVE-2020-3917.
How was this vulnerability addressed?
This vulnerability was addressed with a new entitlement.
Which software and versions are affected by this vulnerability?
The following software versions are affected by this vulnerability: Apple iOS up to and excluding 13.4, Apple iPadOS up to and excluding 13.4, Apple tvOS up to and excluding 13.4, Apple watchOS up to and excluding 6.2.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [reference 1](https://support.apple.com/en-us/HT211103), [reference 2](https://support.apple.com/en-us/HT211102), [reference 3](https://support.apple.com/en-us/HT211101).