CVE-2023-42948
published 2024-07-29CVE-2023-42948: This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating a Mac…
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.17%
6.1th percentile
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating a Mac in macOS Recovery.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.0 | 14.0 |
| apple | macos | >= unspecified < 14 | 14 |
| apple | macos_sonoma | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-42948: macOS Sonoma 14
vendor_apple·2023-09-26·CVSS 3.3
CVE-2023-42948 [LOW] CVE-2023-42948: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42948
Component: System Settings
Impact: A Wi-Fi password may not be deleted when activating a Mac in macOS Recovery
Description: This issue was addressed through improved state management.
CISA
Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
cisa·2023-03-30·CVSS 9.8
CVE-2022-42948 [CRITICAL] CWE-79 Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
Vulnerability: Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
Affected: Fortra Cobalt Strike
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948
Remediation Due Date: 2023-04-20
GHSA
GHSA-89gm-fv57-9hjw: This issue was addressed through improved state management
ghsa_unreviewed·2024-07-29
CVE-2023-42948 [LOW] CWE-200 GHSA-89gm-fv57-9hjw: This issue was addressed through improved state management
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating a Mac in macOS Recovery.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-29
Published