SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28182

The issue was addressed with improved authentication.

MEDIUM 6.5EPSS 0.71%

Does this matter?

Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.

Description

The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.71% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
apple/ipados · apple/iphone os · apple/macos
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.