CVE-2023-32434

Scores

EPSS

0.578medium57.8%
0%20%40%60%80%100%

Percentile: 57.8%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

190CWE-190

Related Vulnerabilities

Exploits

Exploit ID: CVE-2023-32434

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Vulnerable Software (4)

Type: Configuration

Vendor: *

Product: ipados

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",      "versionEndExcluding": "15.7.7",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:apple:ipa...

Source: nvd

Type: Configuration

Vendor: *

Product: iphone_os

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",      "versionEndExcluding": "15.7.7",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:apple:ipa...

Source: nvd

Type: Configuration

Vendor: *

Product: macos

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",      "versionEndExcluding": "15.7.7",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:apple:ipa...

Source: nvd

Type: Configuration

Vendor: *

Product: watchos

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",      "versionEndExcluding": "15.7.7",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:apple:ipa...

Source: nvd

End of list