SB2023121916 - Improper Authentication in Nextcloud Files iOS



SB2023121916 - Improper Authentication in Nextcloud Files iOS

Published: December 19, 2023

Security Bulletin ID SB2023121916
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2023-49790)

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests within the App PIN code. An attacker with physical access can use the application without providing the 4 digit PIN code.


Remediation

Install update from vendor's website.