CVE-2020-35207 describes a vulnerability in the LastPass Password Manager app 4.8.11.2403 for iOS, allowing PIN authentication bypass through runtime manipulation. An attacker could authenticate with any PIN, effectively gaining unauthorized access to the password manager. This issue has a CVSS score of 5.7 (Medium), indicating a physical attack vector with high attack complexity, but high impact on confidentiality and integrity. Despite the potential impact, the vendor considers it outside their threat model as it requires a jailbroken device, and there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.8.11.2403CPE matchmatch criteria | cpe:2.3:a:logmein:lastpass:4.8.11.2403:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.