VDB
CVE-2021-30737
CVE-2021-30737
PUBLISHED
CVSS 8.800000190734863 HIGH
A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.
EPSS 0.40% · 61.1th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.40%
61.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | ipados | 0, 0, 0 |
| Apple | macOS | unspecified, unspecified, * |
| apple | macos | 11.0.1, 11.0.1, 11.0.1 |
| apple | watchos | 0, 0, 0 |
| apple | tvos | 0, 0, 0 |
| apple | iphone_os | 13.0, 13.0, 0 |
| Apple | iOS and iPadOS | unspecified |
| apple | mac_os_x | 10.14.6, 10.14.6, 10.14.6 |
Exploit Intelligence
- https://support.apple.com/en-us/HT212528 (circl)
- https://support.apple.com/en-us/HT212529 (circl)
- https://support.apple.com/en-us/HT212532 (circl)
- https://support.apple.com/en-us/HT212533 (circl)
- https://support.apple.com/en-us/HT212530 (circl)
- https://support.apple.com/en-us/HT212531 (circl)
- https://support.apple.com/en-us/HT212548 (circl)
- https://support.apple.com/kb/HT212548 (vulncheck)
- (vulncheck-reported-exploitation)
- (vulncheck-reported-exploitation)
…and 1 more exploits
Timeline
- May 25, 2021 CVE Published
- Jun 14, 2021 VulnCheck KEV Exploitation
- Sep 9, 2021 EPSS Score
- Sep 15, 2021 EPSS Score
- Nov 6, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 24, 2022 EPSS Score
- Aug 22, 2022 EPSS Score
- Oct 19, 2022 EPSS Score
References
- https://support.apple.com/en-us/HT212528 url
- https://support.apple.com/en-us/HT212529 url
- https://support.apple.com/en-us/HT212532 url
- https://support.apple.com/en-us/HT212533 url
- https://support.apple.com/en-us/HT212530 url
- https://support.apple.com/en-us/HT212531 url
- https://support.apple.com/en-us/HT212548 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-30737 advisory
- https://support.apple.com/en-us/HT212534 advisory
- https://support.apple.com/en-gb/HT212548 advisory