Security readout for executives and security teams
Plain-English summary
Older Readdle Documents for iOS versions exposed user files through its local file-transfer features. The issue allowed any website the user visited to make cross-origin requests and access data through weak server authorization. The affected range is before version 6.9.7.
Executive priority
Prioritize remediation where staff store sensitive files in Readdle Documents. The issue is not KEV-listed, but the data-access impact justifies targeted mobile app inventory and update enforcement.
Technical view
CVE-2019-20801 concerns Readdle Documents for iOS before 6.9.7. Its file-transfer web server allowed requests from any origin, and its WebSocket server lacked authorization control. The stated impact is JavaScript from any website accessing user data via cross-origin requests.
Likely exposure
Exposure is limited to iOS devices running Readdle Documents before 6.9.7, especially where the app's file-transfer web server is enabled or reachable while the user browses the web.
Exploitation context
The provided sources do not report active exploitation, and the CVE is not listed as KEV. The attack condition described is a user visiting any website while the vulnerable app service can be accessed.
Researcher notes
Evidence is sparse: no CVSS, CWE, or detailed affected CPE data is provided. The strongest technical signals are permissive cross-origin behavior on the file-transfer web server and missing WebSocket authorization before 6.9.7.
Mitigation direction
- Upgrade Readdle Documents for iOS to version 6.9.7 or later.
- Check Readdle and Apple App Store guidance for current supported versions.
- Disable or avoid file-transfer server use until devices are updated.
- Use MDM controls to identify and update stale iOS app installs.
Validation and detection
- Inventory iOS devices for Readdle Documents installations and versions.
- Confirm no managed device remains below version 6.9.7.
- Review mobile risk telemetry for unexpected local file-transfer service exposure.
- Document whether business workflows rely on Documents file-transfer features.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-20801 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://apps.apple.com/us/app/documents-by-readdle/id364901807CVE reference · x_refsource_MISC
- https://logicaltrust.net/blog/2019/12/documents.html#authorizationCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
