CVE-2020-35207
LastPass vulnerability analysis and mitigation

Overview

A disputed vulnerability was discovered in the LogMein LastPass Password Manager (com.lastpass.ilastpass) app version 4.8.11.2403 for iOS. The vulnerability, identified as CVE-2020-35207, involves the PIN authentication mechanism for unlocking the vault. The issue was discovered where the PIN authentication could be bypassed by forcing the authentication result to be true through runtime manipulation, effectively allowing authentication with any arbitrary PIN (NVD, LastPass Vulnerabilities).

Technical details

The vulnerability affects the PIN authentication mechanism used for unlocking the LastPass vault. Through runtime manipulation, an attacker could force the authentication result to return true, regardless of the PIN entered. The vulnerability has been assigned a CVSS v3.1 base score of 5.7 (MEDIUM) with the vector string CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating that physical access is required and attack complexity is high (NVD).

Impact

If successfully exploited, the vulnerability would allow an attacker with physical access to the device to bypass the PIN authentication mechanism and gain unauthorized access to the password vault. This could potentially expose all stored credentials and sensitive information within the LastPass vault (NVD).

Exploitability

The vulnerability requires a jailbroken iOS device to exploit, as runtime manipulation of the application is necessary. A proof-of-concept demonstration has been published showing the successful bypass of the PIN authentication mechanism (LastPass Vulnerabilities).

Mitigation and workarounds

LastPass has disputed this vulnerability, stating that it falls outside their threat model which explicitly excludes jailbroken devices. As such, no official fix has been released as the vendor considers this an invalid attack scenario (NVD).

Additional resources


SourceThis report was generated using AI

Related LastPass vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-16371HIGH8.2
  • LastPass logoLastPass
  • lastpass
NoYesSep 16, 2019
CVE-2013-5113MEDIUM6.8
  • LastPass logoLastPass
  • cpe:2.3:a:logmein:lastpass
NoYesJan 31, 2020
CVE-2013-5114MEDIUM6.1
  • LastPass logoLastPass
  • cpe:2.3:a:logmein:lastpass
NoYesJan 31, 2020
CVE-2020-35208MEDIUM5.7
  • LastPass logoLastPass
  • cpe:2.3:a:logmein:lastpass
NoYesDec 12, 2020
CVE-2020-35207MEDIUM5.7
  • LastPass logoLastPass
  • lastpass
NoYesDec 12, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management