CVE-2020-29613

MEDIUM

iPadOS < 14.3 - Domain Spoofing via Enterprise Application Installation Prompt

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.3 and iPadOS 14.3. An enterprise application installation prompt may display the wrong domain.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212003

Scores

CVSS v3 5.5
EPSS 0.0058
EPSS Percentile 43.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (2)
apple/ipados < 14.3
apple/iphone_os < 14.3
Published Apr 02, 2021
Tracked Since Feb 18, 2026