CVSS 3.1 Score 4.3 of 10 (medium)


Published Dec 22, 2023
Updated: Dec 29, 2023
CWE ID 287


CVE-2023-49790 is a vulnerability affecting the Nextcloud iOS Files app prior to version 4.9.2, which allows users to interact with the self-hosted productivity platform Nextcloud on iOS devices. The vulnerability allows users to access the application without providing the 4 digit PIN code, posing a risk to the security of organizations using the app. To remediate this vulnerability, users should upgrade to version 4.9.2 of the Nextcloud iOS Files app, as no known workarounds are available. The vulnerability has a base severity rating of MEDIUM and an exploitability score of 0.9 out of 10 according to [email protected].


Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-49790 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options