5.5

CVE-2024-23241

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able to leak sensitive user information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPad OS Version < 17.4
Apple ≫ iPhone OS Version < 17.4
Apple ≫ macOS Version >= 14.0 < 14.4
Apple ≫ tvOS Version < 17.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA-ADP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-922 Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

http://seclists.org/fulldisclosure/2024/Mar/21
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/25
Mailing List
https://support.apple.com/kb/HT214081
https://support.apple.com/kb/HT214084
https://support.apple.com/kb/HT214086
https://support.apple.com/en-us/HT214081
Vendor Advisory
https://support.apple.com/en-us/HT214084
Vendor Advisory
https://support.apple.com/en-us/HT214086
Vendor Advisory
https://support.apple.com/en-us/120882
https://support.apple.com/en-us/120893
https://support.apple.com/en-us/120895