VDB
CVE-2023-41991
CVE-2023-41991
PUBLISHED
KEV
Es besteht eine Schwachstelle in Apple iOS und Apple iPadOS. Dieser Fehler besteht in der Sicherheitskomponente aufgrund einer unsachgemäßen Zertifikatsvalidierung. Ein entfernter Angreifer kann über eine bösartige Anwendung diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 3.90% · 88.5th percentile
Risk Scores
EPSS Score
3.90%
88.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple iOS <17 | |
| Apple | Apple iOS <16.7 | |
| Apple | Apple macOS Ventura <13.6 | |
| Apple | Apple macOS Sonoma <14 | |
| Apple | Apple iPadOS <16.7 | |
| Apple | Apple iPadOS <17 | |
| Apple | Apple macOS Monterey <12.7 |
Timeline
- Sep 21, 2023 PoC Published
- Sep 21, 2023 CVE Published
- Sep 22, 2023 EPSS Score
- Sep 25, 2023 CISA KEV Added
- Oct 3, 2023 EPSS Score
- Nov 25, 2023 EPSS Score
- Jan 17, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Apr 1, 2024 EPSS Score
- Jun 4, 2024 EPSS Score
- Jul 17, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2427.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2427 advisory
- https://isc.sans.edu/diary/rss/30238 advisory
- https://support.apple.com/en-us/HT213927 advisory
- https://support.apple.com/en-us/HT213926 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2453.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2453 advisory
- https://support.apple.com/en-us/HT213931 advisory
- https://support.apple.com/en-us/HT213932 advisory
- https://support.apple.com/en-us/HT213940 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2454.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2454 advisory
- https://support.apple.com/en-us/HT213938 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit