CVE-2016-4722Improper Input Validation in Apple Iphone OS

Severity
5.9MEDIUMNVD
EPSS
3.3%
top 12.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 17

Description

The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attacks and cause a denial of service via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

NVDapple/mac_os_x10.11.6
NVDapple/iphone_os9.3.5
Appleapple/ios10
Appleapple/macos_sierra10.12

🔴Vulnerability Details

1
GHSA
GHSA-wr6h-frm4-2487: The IDS - Connectivity component in Apple iOS before 10 and OS X before 102022-05-17

📋Vendor Advisories

2
Apple
CVE-2016-4722: macOS Sierra 10.122016-09-20
Apple
CVE-2016-4722: iOS 102016-09-13