Lucene search

K
cveAppleCVE-2023-42941
HistoryJan 10, 2024 - 10:15 p.m.

CVE-2023-42941

2024-01-1022:15:50
apple
web.nvd.nist.gov
24
ios
ipados
17.2
security
vulnerability
denial-of-service
bluetooth packets
cve-2023-42941
nvd

CVSS3

4.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

3.9

Confidence

High

EPSS

0

Percentile

9.0%

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets.

Affected configurations

Nvd
Vulners
Node
appleipadosRange<17.2
OR
appleiphone_osRange<17.2
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "iOS and iPadOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "17.2",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

3.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-42941