5.5

CVE-2024-40850

A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to access user-sensitive data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 17.7
Apple ≫ iPhone OS Version < 17.7
Apple ≫ macOS Version < 13.7
Apple ≫ macOS Version >= 14.0 < 14.7
Apple ≫ tvOS Version < 18.0
Apple ≫ visionOS Version < 2.0
Apple ≫ watchOS Version < 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.apple.com/en-us/121238
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121250
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121234
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121246
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121247
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121249
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121240
Vendor Advisory
Release Notes
https://support.apple.com/en-us/121248
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2024/Sep/33
http://seclists.org/fulldisclosure/2024/Sep/32
http://seclists.org/fulldisclosure/2024/Sep/36
http://seclists.org/fulldisclosure/2024/Sep/41
http://seclists.org/fulldisclosure/2024/Sep/39
http://seclists.org/fulldisclosure/2024/Sep/40