Improper Initialization in iPadOS and Apple iOS - CVE-2021-1780

 

Improper Initialization in iPadOS and Apple iOS - CVE-2021-1780

Published: June 3, 2021


Vulnerability identifier: #VU53786
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1780
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform DoS attack.

The vulnerability exists due to improper initialization within the Bluetooth subsystem. An attacker with physical proximity to device can send specially crafted packets to the system and perform a denial of service (DoS) attack.


Affected software

iPadOS
Apple iOS

How to mitigate CVE-2021-1780

Install updates from vendor's website.

iPadOS - update to 14.4 18D52
Apple iOS - update to 14.4 18D52

External References

Related Security Bulletins