3.3

CVE-2022-22656

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ macOS X Version >= 10.15 < 10.15.7
Apple ≫ macOS X Version 10.15.7 Update security_update_2022-001
Apple ≫ macOS X Version 10.15.7 Update security_update_2022-002
Apple ≫ macOS Version >= 11.6 < 11.6.5
Apple ≫ macOS Version >= 12.0 < 12.3
Apple ≫ macOS Version 10.15.7 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.174
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://support.apple.com/en-us/HT213183
Vendor Advisory
https://support.apple.com/en-us/HT213184
Vendor Advisory
https://support.apple.com/en-us/HT213185
Vendor Advisory