Vulnerability Name:

CVE-2020-7463 (CCN-198983)

Assigned:2020-09-02
Published:2020-09-02
Updated:2023-01-09
Summary:
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-7463

Source: secteam@freebsd.org
Type: Mailing List, Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Mailing List, Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Mailing List, Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Mailing List, Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Mailing List, Third Party Advisory
secteam@freebsd.org

Source: XF
Type: UNKNOWN
freebsd-cve20207463-dos(198983)

Source: secteam@freebsd.org
Type: Vendor Advisory
secteam@freebsd.org

Source: CCN
Type: Apple security document HT212317
About the security content of iOS 14.5 and iPadOS 14.5

Source: CCN
Type: Apple security document HT212318
About the security content of Safari 14.1

Source: CCN
Type: Apple security document HT212319
About the security content of iTunes 12.11.3 for Windows

Source: CCN
Type: Apple security document HT212321
About the security content of iCloud for Windows 12.3

Source: CCN
Type: Apple security document HT212325
About the security content of macOS Big Sur 11.3

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: secteam@freebsd.org
Type: Third Party Advisory
secteam@freebsd.org

Source: CCN
Type: FreeBSD Security Advisory FreeBSD-SA-20:25.sctp
SCTP socket use-after-free bug

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-7463

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:freebsd:freebsd:12.1:stable:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:12.1:release:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:11.4:stable:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:11.3:release:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:14.0.0:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:11.4:release:*:*:*:*:*:*
  • OR cpe:/a:apple:icloud:12.3:*:*:*:*:windows:*:*

  • * Denotes that component is vulnerable
    BACK
    freebsd freebsd 12.1 stable
    freebsd freebsd 12.1 release
    freebsd freebsd 11.4 stable
    freebsd freebsd 11.3 release
    apple safari 14.0.0
    freebsd freebsd 11.4 release
    apple icloud 12.3