Lucene search

K
cveAppleCVE-2022-46717
HistoryApr 10, 2023 - 7:15 p.m.

CVE-2022-46717

2023-04-1019:15:07
apple
web.nvd.nist.gov
45
cve-2022-46717
logic issue
ios 16.2
ipados 16.2
accessibility
apple watch security
information security

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.1

Confidence

Low

EPSS

0.001

Percentile

21.6%

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features

Affected configurations

Nvd
Vulners
Node
appleipadosRange<16.2
OR
appleiphone_osRange<16.2
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "iOS and iPadOS",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "16.2",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.1

Confidence

Low

EPSS

0.001

Percentile

21.6%

Related for CVE-2022-46717