CVE-2024-23277

5 documents4 sources
Severity
5.9MEDIUM
EPSS
0.3%
top 49.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8

Description

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages5 packages

CVEListV5apple/macos< 14.4
NVDapple/macos14.014.4
NVDapple/ipad_os< 17.4
CVEListV5apple/ios_and_ipados< 17.4
NVDapple/iphone_os17.017.4

🔴Vulnerability Details

2
CVEList
CVE-2024-23277: The issue was addressed with improved checks2024-03-08
GHSA
GHSA-j6q4-78q3-g22f: The issue was addressed with improved checks2024-03-08

📋Vendor Advisories

2
Apple
CVE-2024-23277: macOS Sonoma 14.42024-03-07
Apple
CVE-2024-23277: iOS 17.4 and iPadOS 17.42024-03-05