CVE-2020-3887
Estado: ModificadaMedia (4.3)—
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.19%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
CWE
- NVD-CWE-Other
Referencias
- https://support.apple.com/HT211101
- https://support.apple.com/HT211102
- https://support.apple.com/HT211104
- https://support.apple.com/HT211105
- https://support.apple.com/HT211106
- https://support.apple.com/HT211107
- https://support.apple.com/HT211101
- https://support.apple.com/HT211102
- https://support.apple.com/HT211104
- https://support.apple.com/HT211105
- https://support.apple.com/HT211106
- https://support.apple.com/HT211107
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-3887",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "Apple",
"product": "iOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "iOS 13.4 and iPadOS 13.4",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "tvOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "tvOS 13.4",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "Safari",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "Safari 13.1",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "iTunes for Windows",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "iTunes for Windows 12.10.5",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "iCloud for Windows",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "iCloud for Windows 10.9.3",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "iCloud for Windows (Legacy)",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "iCloud for Windows 7.18",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-04-01T18:15:15.880",
"references": [
{
"url": "https://support.apple.com/HT211101",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211102",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211104",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211105",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211106",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211107",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT211101",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT211102",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT211104",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT211105",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT211106",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT211107",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated."
},
{
"lang": "es",
"value": "Se abordó un problema lógico con restricciones mejoradas. Este problema es corregido en iOS versión 13.4 y iPadOS versión 13.4, tvOS versión 13.4, Safari versión 13.1, iTunes para Windows versión 12.10.5, iCloud para Windows versión 10.9.3, iCloud para Windows versión 7.18. El origen de una descarga puede ser asociado incorrectamente."
}
],
"lastModified": "2026-06-17T03:19:12.307",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "C0F56F52-3A35-4C68-872B-9DC349664260",
"versionEndExcluding": "7.18"
},
{
"criteria": "cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "9BD7597B-A879-4CDE-AB4E-B664BFF83138",
"versionEndExcluding": "10.9.3",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "82E6396E-8C78-4EED-88EC-B97C9B4C2DA9",
"versionEndExcluding": "12.10.5"
},
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0043E6A5-C84C-4538-A6FB-A64882B0F828",
"versionEndExcluding": "13.1"
},
{
"criteria": "cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A754595C-30B0-4E62-8ECF-E671F6C3DC57",
"versionEndExcluding": "13.4"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09DD8CD4-AF42-4A2B-8DF0-AED34E43FDD8",
"versionEndExcluding": "13.4"
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D72D358-8126-4B3C-97E9-A01731C38D45",
"versionEndExcluding": "13.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}