Risk Scores
CVSS v2.0
4.300000190734863
EPSS Score
0.11%
29.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | tvos | 0, 0, 0 |
| apple | ipados | 0, 0, 0 |
| Apple | Safari | |
| apple | mac_os_x | 0, 0, 0 |
| Apple | macOS | |
| apple | watchos | 0, 0, 0 |
| Apple | N/A | |
| apple | iphone_os | 0, 0, 0 |
| Red Hat | VPN | n/a |
Timeline
- Dec 16, 2019 PoC Published
- Oct 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 23, 2021 EPSS Score
- Oct 24, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 25, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
References
- https://support.apple.com/en-us/HT211289 advisory
- https://support.apple.com/en-us/HT211288 advisory
- https://support.apple.com/en-us/HT211292 advisory
- https://support.apple.com/en-us/HT211291 advisory
- https://support.apple.com/en-us/HT211290 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899 url
- https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/ url
- https://support.apple.com/kb/HT211288 url
- https://support.apple.com/kb/HT211290 url
- https://support.apple.com/kb/HT211289 url
- 20200717 APPLE-SA-2020-07-15-3 tvOS 13.4.8 mailing-list
- 20200717 APPLE-SA-2020-07-15-2 macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra mailing-list
- 20200717 APPLE-SA-2020-07-15-1 iOS 13.6 and iPadOS 13.6 mailing-list
- [oss-security] 20200813 Blind in/on-path attacks against VPN-tunneled connections (CVE-2019-14899 follow-up) mailing-list
- https://support.apple.com/kb/HT211850 url
- [oss-security] 20201007 Re: [CVE-2019-14899] Inferring and hijacking VPN-tunneled TCP connections. mailing-list
- https://support.apple.com/kb/HT211931 url
- 20201115 APPLE-SA-2020-11-13-3 Additional information for APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 mailing-list
- 20201215 APPLE-SA-2020-12-14-4 Additional information for APPLE-SA-2020-11-13-1 macOS Big Sur 11.0.1 mailing-list
- [oss-security] 20210704 Re: Blind in/on-path attacks against VPN-tunneled connections (CVE-2019-14899 follow-up) mailing-list
…and 5 more