CVE-2023-42897

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.
References
Link Resource
http://seclists.org/fulldisclosure/2023/Dec/7 Third Party Advisory
https://support.apple.com/en-us/HT214035 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

13 Dec 2023, 20:57

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
References () http://seclists.org/fulldisclosure/2023/Dec/7 - () http://seclists.org/fulldisclosure/2023/Dec/7 - Third Party Advisory
References () https://support.apple.com/en-us/HT214035 - () https://support.apple.com/en-us/HT214035 - Release Notes, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
First Time Apple
Apple ipados
Apple iphone Os

13 Dec 2023, 01:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2023/Dec/7 -

12 Dec 2023, 13:43

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó con controles mejorados. Este problema se solucionó en iOS 17.2 y iPadOS 17.2. Un atacante con acceso físico puede utilizar Siri para acceder a datos confidenciales del usuario.

12 Dec 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 01:15

Updated : 2023-12-13 20:57


NVD link : CVE-2023-42897

Mitre link : CVE-2023-42897

CVE.ORG link : CVE-2023-42897


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados