ID

VAR-202210-1460


CVE

CVE-2022-32904


TITLE

apple's  macOS  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-022856

DESCRIPTION

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to access user-sensitive data. apple's macOS Exists in unspecified vulnerabilities.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2022-32904 // JVNDB: JVNDB-2022-022856 // VULHUB: VHN-424993

AFFECTED PRODUCTS

vendor:applemodel:macosscope:gteversion:11.0

Trust: 1.0

vendor:applemodel:macosscope:ltversion:12.6

Trust: 1.0

vendor:applemodel:macosscope:ltversion:11.7

Trust: 1.0

vendor:applemodel:macosscope:gteversion:12.0

Trust: 1.0

vendor:アップルmodel:macosscope:eqversion:12.0 that's all 12.6

Trust: 0.8

vendor:アップルmodel:macosscope:eqversion:11.0 that's all 11.7

Trust: 0.8

vendor:アップルmodel:macosscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-022856 // NVD: CVE-2022-32904

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-32904
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-32904
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202210-1629
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-32904
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2022-32904
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-022856 // CNNVD: CNNVD-202210-1629 // NVD: CVE-2022-32904

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-022856 // NVD: CVE-2022-32904

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1629

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202210-1629

PATCH

title:HT213444 Apple  Security updateurl:https://support.apple.com/en-us/HT213443

Trust: 0.8

title:Apple macOS Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=212657

Trust: 0.6

sources: JVNDB: JVNDB-2022-022856 // CNNVD: CNNVD-202210-1629

EXTERNAL IDS

db:NVDid:CVE-2022-32904

Trust: 3.3

db:JVNDBid:JVNDB-2022-022856

Trust: 0.8

db:AUSCERTid:ESB-2022.5300

Trust: 0.6

db:CNNVDid:CNNVD-202210-1629

Trust: 0.6

db:VULHUBid:VHN-424993

Trust: 0.1

sources: VULHUB: VHN-424993 // JVNDB: JVNDB-2022-022856 // CNNVD: CNNVD-202210-1629 // NVD: CVE-2022-32904

REFERENCES

url:https://support.apple.com/en-us/ht213488

Trust: 2.3

url:https://support.apple.com/en-us/ht213443

Trust: 1.7

url:https://support.apple.com/en-us/ht213444

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-32904

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-32904/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.5300

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-macos-multiple-vulnerabilities-39702

Trust: 0.6

sources: VULHUB: VHN-424993 // JVNDB: JVNDB-2022-022856 // CNNVD: CNNVD-202210-1629 // NVD: CVE-2022-32904

SOURCES

db:VULHUBid:VHN-424993
db:JVNDBid:JVNDB-2022-022856
db:CNNVDid:CNNVD-202210-1629
db:NVDid:CVE-2022-32904

LAST UPDATE DATE

2024-08-14T12:56:57.660000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-424993date:2022-11-02T00:00:00
db:JVNDBid:JVNDB-2022-022856date:2023-11-21T02:28:00
db:CNNVDid:CNNVD-202210-1629date:2022-11-03T00:00:00
db:NVDid:CVE-2022-32904date:2022-11-02T19:08:31.807

SOURCES RELEASE DATE

db:VULHUBid:VHN-424993date:2022-11-01T00:00:00
db:JVNDBid:JVNDB-2022-022856date:2023-11-21T00:00:00
db:CNNVDid:CNNVD-202210-1629date:2022-10-24T00:00:00
db:NVDid:CVE-2022-32904date:2022-11-01T20:15:19.010