VDB

CVE-2021-1863

CVE-2021-1863 PUBLISHED CVSS 2.4000000953674316 LOW

An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.

EPSS 0.29% · 21.7th percentile

Risk Scores

CVSS 3.1
2.4000000953674316
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.29%
21.7th percentile

Affected Products

VendorProductVersions
AppleiOS and iPadOSunspecified
appleipados0
appleiphone_os0

Timeline

  • Sep 8, 2021 CVE Published
  • Sep 9, 2021 EPSS Score
  • Nov 6, 2021 EPSS Score
  • Jan 2, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 1, 2022 EPSS Score
  • Apr 28, 2022 EPSS Score
  • Jun 25, 2022 EPSS Score
  • Aug 22, 2022 EPSS Score
  • Oct 19, 2022 EPSS Score
  • Dec 16, 2022 EPSS Score
  • Feb 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›