VulnerabilityModified
CVE-2023-40418
An authentication issue was addressed with improved state management.
MEDIUM 5.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
An authentication issue was addressed with improved state management. This issue is fixed in watchOS 10. An Apple Watch Ultra may not lock when using the Depth app.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Affected
- apple/watchos
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2023/Oct/9Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT213937Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2023/Oct/9Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT213937Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213937
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.