Lucene search

K
cveAppleCVE-2023-41993
HistorySep 21, 2023 - 7:15 p.m.

CVE-2023-41993

2023-09-2119:15:11
CWE-754
apple
web.nvd.nist.gov
398
In Wild
35
cve-2023-41993
safari 17
ios 16.7
ipados 16.7
macos sonoma 14
arbitrary code execution
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

70.5%

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
appleipadosRange<17.0.1
OR
appleiphone_osRange<17.0.1
OR
applemacosRange<14.0
Node
fedoraprojectfedoraMatch37
OR
fedoraprojectfedoraMatch38
OR
fedoraprojectfedoraMatch39
Node
debiandebian_linuxMatch11.0
OR
debiandebian_linuxMatch12.0
Node
oraclegraalvmMatch20.3.13enterprise
OR
oraclegraalvmMatch21.3.9enterprise
OR
oraclejdkMatch1.8.0update401
OR
oraclejreMatch1.8.0update401
Node
netappcloud_insights_acquisition_unitMatch-
OR
netappcloud_insights_storage_workload_security_agentMatch-
OR
netapponcommand_insightMatch-
OR
netapponcommand_workflow_automationMatch-
Node
webkitgtkwebkitgtk\+Range<2.42.2
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
applemacos*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
fedoraprojectfedora37cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
fedoraprojectfedora38cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
fedoraprojectfedora39cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
debiandebian_linux11.0cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
debiandebian_linux12.0cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
oraclegraalvm20.3.13cpe:2.3:a:oracle:graalvm:20.3.13:*:*:*:enterprise:*:*:*
oraclegraalvm21.3.9cpe:2.3:a:oracle:graalvm:21.3.9:*:*:*:enterprise:*:*:*
Rows per page:
1-10 of 171

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "14",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

70.5%