CVE-2021-30694
published 2021-09-08CVE-2021-30694: An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.95%
57.7th percentile
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 14.6 | 14.6 |
| apple | ipados | < 14.6 | 14.6 |
| apple | iphone_os | < 14.6 | 14.6 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.14 – 10.14.5 | — |
| apple | mac_os_x | 10.15 – 10.15.6 | — |
| apple | macos | >= 11.0 < 11.4 | 11.4 |
| apple | macos | >= unspecified < 11.4 | 11.4 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-003_catalina | — | — |
| apple | security_update_2021-004_mojave | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30694: Security Update 2021-003 Catalina
vendor_apple·2021-05-24·CVSS 5.5
CVE-2021-30694 [MEDIUM] CVE-2021-30694: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30694
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An information disclosure issue was addressed with improved state management.
Apple
CVE-2021-30694: Security Update 2021-004 Mojave
vendor_apple·2021-05-24·CVSS 5.5
CVE-2021-30694 [MEDIUM] CVE-2021-30694: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30694
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An information disclosure issue was addressed with improved state management.
Apple
CVE-2021-30694: macOS Big Sur 11.4
vendor_apple·2021-05-24·CVSS 5.5
CVE-2021-30694 [MEDIUM] CVE-2021-30694: macOS Big Sur 11.4
Apple Security Update: About the security content of macOS Big Sur 11.4
Product: macOS Big Sur
Version: 11.4
CVE: CVE-2021-30694
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An information disclosure issue was addressed with improved state management.
GHSA
GHSA-p89h-86gx-x9fw: An information disclosure issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-30694 [MEDIUM] GHSA-p89h-86gx-x9fw: An information disclosure issue was addressed with improved state management
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212528https://support.apple.com/en-us/HT212529https://support.apple.com/en-us/HT212530https://support.apple.com/en-us/HT212531https://support.apple.com/en-us/HT212528https://support.apple.com/en-us/HT212529https://support.apple.com/en-us/HT212530https://support.apple.com/en-us/HT212531
2021-09-08
Published