2023-09-27 16:00:29 +00:00
{
"id" : "CVE-2023-40406" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2023-09-27T15:19:08.360" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:19:23.317" ,
2023-11-07 21:03:21 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-09-27 16:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, macOS Ventura 13.6, macOS Sonoma 14. An app may be able to read arbitrary files."
2023-09-28 18:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "El problema se solucion\u00f3 con controles mejorados. Este problema se solucion\u00f3 en macOS Monterey 12.7, macOS Ventura 13.6, macOS Sonoma 14. Es posible que una aplicaci\u00f3n pueda leer archivos arbitrarios."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM" ,
2023-09-28 18:00:28 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-28 18:00:28 +00:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "12.0.0" ,
"versionEndExcluding" : "12.7" ,
"matchCriteriaId" : "38A33420-FEB8-498F-A513-5DC0EEC52B1E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "13.0" ,
"versionEndExcluding" : "13.6" ,
"matchCriteriaId" : "7A78DA60-AE3B-4B3C-B338-97DAFABEBB1F"
}
]
}
]
2023-09-27 16:00:29 +00:00
}
] ,
"references" : [
2023-11-07 21:03:21 +00:00
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/3" ,
"source" : "product-security@apple.com"
} ,
2023-10-03 08:00:28 +00:00
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/5" ,
2023-10-12 02:00:30 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
2023-10-03 08:00:28 +00:00
} ,
2023-11-07 21:03:21 +00:00
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/6" ,
"source" : "product-security@apple.com"
} ,
2023-09-27 16:00:29 +00:00
{
"url" : "https://support.apple.com/en-us/HT213931" ,
2023-09-28 18:00:28 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2023-09-27 16:00:29 +00:00
} ,
{
"url" : "https://support.apple.com/en-us/HT213932" ,
2023-09-28 18:00:28 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2023-09-27 16:00:29 +00:00
} ,
{
"url" : "https://support.apple.com/en-us/HT213940" ,
2023-09-28 18:00:28 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/3" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/5" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/6" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://support.apple.com/en-us/HT213931" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://support.apple.com/en-us/HT213932" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://support.apple.com/en-us/HT213940" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2023-09-27 16:00:29 +00:00
}
]
}