{"api_version":"1","generated_at":"2026-07-23T11:38:17+00:00","cve":"CVE-2020-27951","urls":{"html":"https://cve.report/CVE-2020-27951","api":"https://cve.report/api/cve/CVE-2020-27951.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-27951","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-27951"},"summary":{"title":"CVE-2020-27951","description":"This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2021-04-02 18:15:00","updated_at":"2021-04-07 18:11:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.apple.com/en-us/HT212004","name":"https://support.apple.com/en-us/HT212004","refsource":"MISC","tags":[],"title":"About the security content of iOS 12.5 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/en-us/HT212003","name":"https://support.apple.com/en-us/HT212003","refsource":"MISC","tags":[],"title":"About the security content of iOS 14.3 and iPadOS 14.3 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/en-us/HT212006","name":"https://support.apple.com/en-us/HT212006","refsource":"MISC","tags":[],"title":"About the security content of watchOS 6.3 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/en-us/HT212009","name":"https://support.apple.com/en-us/HT212009","refsource":"MISC","tags":[],"title":"About the security content of watchOS 7.2 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-27951","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27951","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"27951","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"ipados","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"27951","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"27951","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"watchos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-27951","ASSIGNER":"product-security@apple.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apple","product":{"product_data":[{"product_name":"iOS and iPadOS","version":{"version_data":[{"version_affected":"<","version_value":"14.3"}]}},{"product_name":"iOS","version":{"version_data":[{"version_affected":"<","version_value":"12.5"}]}},{"product_name":"watchOS","version":{"version_data":[{"version_affected":"<","version_value":"6.3"}]}},{"product_name":"watchOS","version":{"version_data":[{"version_affected":"<","version_value":"7.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unauthorized code execution may lead to an authentication policy violation"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://support.apple.com/en-us/HT212003","name":"https://support.apple.com/en-us/HT212003"},{"refsource":"MISC","url":"https://support.apple.com/en-us/HT212009","name":"https://support.apple.com/en-us/HT212009"},{"refsource":"MISC","url":"https://support.apple.com/en-us/HT212004","name":"https://support.apple.com/en-us/HT212004"},{"refsource":"MISC","url":"https://support.apple.com/en-us/HT212006","name":"https://support.apple.com/en-us/HT212006"}]},"description":{"description_data":[{"lang":"eng","value":"This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation."}]}},"nvd":{"publishedDate":"2021-04-02 18:15:00","lastModifiedDate":"2021-04-07 18:11:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","versionEndExcluding":"14.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"14.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"12.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"27951","Ordinal":"189687","Title":"CVE-2020-27951","CVE":"CVE-2020-27951","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"27951","Ordinal":"1","NoteData":"This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"27951","Ordinal":"2","NoteData":"2021-04-02","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"27951","Ordinal":"3","NoteData":"2021-04-02","Type":"Other","Title":"Modified"}]}}}