Vulnerability Name: | CVE-2021-30714 (CCN-202329) |
Assigned: | 2021-05-24 |
Published: | 2021-05-24 |
Updated: | 2021-09-16 |
Summary: | A race condition was addressed with improved state handling. This issue is fixed in iOS 14.6 and iPadOS 14.6. An application may be able to cause unexpected system termination or write kernel memory.
|
CVSS v3 Severity: | 6.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H) 5.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): High Availibility (A): High | 7.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) 6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): Partial | 6.2 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): None Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-362
|
Vulnerability Consequences: | Denial of Service |
References: | Source: MITRE Type: CNA CVE-2021-30714
Source: XF Type: UNKNOWN apple-ios-cve202130714-dos(202329)
Source: CCN Type: Apple security document HT212528 About the security content of iOS 14.6 and iPadOS 14.6
Source: MISC Type: Release Notes, Vendor Advisory https://support.apple.com/en-us/HT212528
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 14.6)OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 14.6) Configuration CCN 1: cpe:/o:apple:ipados:14.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:14.5:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |