Lucene search

K
cveAppleCVE-2022-32871
HistoryApr 10, 2023 - 7:15 p.m.

CVE-2022-32871

2023-04-1019:15:06
apple
web.nvd.nist.gov
40
ios
16
cve-2022-32871
security
privacy
siri
vulnerability

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.1

Confidence

Low

EPSS

0.001

Percentile

18.9%

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to a device may be able to use Siri to access private calendar information

Affected configurations

Nvd
Vulners
Node
appleiphone_osRange<16.0
VendorProductVersionCPE
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "iOS",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "16",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.1

Confidence

Low

EPSS

0.001

Percentile

18.9%

Related for CVE-2022-32871