An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by forcing the authentication result to be true through runtime manipulation. In other words, an attacker could authenticate with an arbitrary password. NOTE: the vendor has indicated that this is not an attack of interest within the context of their threat model, which excludes jailbroken devices
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-15T15:32:47.977Z
Reserved: 2020-12-12T00:00:00
Link: CVE-2020-35208
Updated: 2024-08-04T17:02:07.033Z
Status : Modified
Published: 2020-12-12T19:15:11.730
Modified: 2024-11-21T05:26:59.430
Link: CVE-2020-35208
No data.
OpenCVE Enrichment
No data.
Weaknesses