ID

VAR-202207-1442


CVE

CVE-2022-32845


TITLE

Vulnerabilities in multiple Apple products

Trust: 0.8

sources: JVNDB: JVNDB-2022-018208

DESCRIPTION

This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox. iPadOS , iOS , macOS Unspecified vulnerabilities exist in multiple Apple products.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. iOS 15.6 and iPadOS 15.6

Trust: 1.8

sources: NVD: CVE-2022-32845 // JVNDB: JVNDB-2022-018208 // VULHUB: VHN-424934 // VULMON: CVE-2022-32845

AFFECTED PRODUCTS

vendor:applemodel:watchosscope:ltversion:8.7

Trust: 1.0

vendor:applemodel:ipadosscope:ltversion:15.6

Trust: 1.0

vendor:applemodel:iphone osscope:ltversion:15.6

Trust: 1.0

vendor:applemodel:macosscope:ltversion:12.5

Trust: 1.0

vendor:applemodel:macosscope:gteversion:12.0

Trust: 1.0

vendor:アップルmodel:watchosscope:eqversion:8.7

Trust: 0.8

vendor:アップルmodel:ipadosscope: - version: -

Trust: 0.8

vendor:アップルmodel:iosscope: - version: -

Trust: 0.8

vendor:アップルmodel:macosscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-018208 // NVD: CVE-2022-32845

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-32845
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-32845
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202207-2015
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-32845
baseSeverity: CRITICAL
baseScore: 10.0
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2022-32845
baseSeverity: CRITICAL
baseScore: 10.0
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-018208 // CNNVD: CNNVD-202207-2015 // NVD: CVE-2022-32845

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-018208 // NVD: CVE-2022-32845

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202207-2015

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-202207-2015

PATCH

title:HT213345 Apple  Security updateurl:https://support.apple.com/en-us/HT213340

Trust: 0.8

title:Multiple Apple product Fixes for permissions and access control issues vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=209235

Trust: 0.6

title:Apple: iOS 15.6 and iPadOS 15.6url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=25de7f37f4830a629a57f79175aeaa2a

Trust: 0.1

title:Apple: macOS Monterey 12.5url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=c765c13fa342a7957a4e91e6dc3d34f4

Trust: 0.1

sources: VULMON: CVE-2022-32845 // JVNDB: JVNDB-2022-018208 // CNNVD: CNNVD-202207-2015

EXTERNAL IDS

db:NVDid:CVE-2022-32845

Trust: 3.4

db:JVNDBid:JVNDB-2022-018208

Trust: 0.8

db:AUSCERTid:ESB-2022.3563

Trust: 0.6

db:CS-HELPid:SB2022072101

Trust: 0.6

db:CS-HELPid:SB2022072106

Trust: 0.6

db:CNNVDid:CNNVD-202207-2015

Trust: 0.6

db:VULHUBid:VHN-424934

Trust: 0.1

db:VULMONid:CVE-2022-32845

Trust: 0.1

sources: VULHUB: VHN-424934 // VULMON: CVE-2022-32845 // JVNDB: JVNDB-2022-018208 // CNNVD: CNNVD-202207-2015 // NVD: CVE-2022-32845

REFERENCES

url:https://support.apple.com/en-us/ht213346

Trust: 2.3

url:https://support.apple.com/en-us/ht213340

Trust: 1.7

url:https://support.apple.com/en-us/ht213345

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-32845

Trust: 0.8

url:https://vigilance.fr/vulnerability/apple-macos-12-multiple-vulnerabilities-38873

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022072101

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.3563

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022072106

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-32845/

Trust: 0.6

url:https://support.apple.com/kb/ht213346

Trust: 0.1

sources: VULHUB: VHN-424934 // VULMON: CVE-2022-32845 // JVNDB: JVNDB-2022-018208 // CNNVD: CNNVD-202207-2015 // NVD: CVE-2022-32845

SOURCES

db:VULHUBid:VHN-424934
db:VULMONid:CVE-2022-32845
db:JVNDBid:JVNDB-2022-018208
db:CNNVDid:CNNVD-202207-2015
db:NVDid:CVE-2022-32845

LAST UPDATE DATE

2024-08-14T12:51:06.334000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-424934date:2023-01-09T00:00:00
db:JVNDBid:JVNDB-2022-018208date:2023-10-19T03:06:00
db:CNNVDid:CNNVD-202207-2015date:2022-09-28T00:00:00
db:NVDid:CVE-2022-32845date:2023-01-09T16:41:59.350

SOURCES RELEASE DATE

db:VULHUBid:VHN-424934date:2022-09-23T00:00:00
db:JVNDBid:JVNDB-2022-018208date:2023-10-19T00:00:00
db:CNNVDid:CNNVD-202207-2015date:2022-07-20T00:00:00
db:NVDid:CVE-2022-32845date:2022-09-23T19:15:13.573