Lucene search

K
cveAppleCVE-2023-40529
HistoryJan 10, 2024 - 10:15 p.m.

CVE-2023-40529

2024-01-1022:15:48
apple
web.nvd.nist.gov
26
cve-2023-40529
ios 17
ipados 17
security
sensitive information
redaction

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.2

Confidence

Low

EPSS

0

Percentile

12.7%

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.

Affected configurations

Nvd
Vulners
Node
appleipadosRange<17.0
OR
appleiphone_osRange<17.0
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "iOS and iPadOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "17",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

2.2

Confidence

Low

EPSS

0

Percentile

12.7%

Related for CVE-2023-40529