VulnerabilityModified
CVE-2024-23218
An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
MEDIUM 5.9EPSS 0.99%
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/120304
- https://support.apple.com/en-us/120306
- https://support.apple.com/en-us/120309
- https://support.apple.com/en-us/120311
- https://support.apple.com/en-us/120880
- https://support.apple.com/en-us/120884
- https://support.apple.com/en-us/120886
- http://seclists.org/fulldisclosure/2024/Jan/33Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/36Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/39Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/40Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/22
- http://seclists.org/fulldisclosure/2024/Mar/23
- https://support.apple.com/en-us/HT214055Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214059Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214060Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214061Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214055
- https://support.apple.com/kb/HT214059
- https://support.apple.com/kb/HT214061
- https://support.apple.com/kb/HT214082
- https://support.apple.com/kb/HT214083
- https://support.apple.com/kb/HT214085
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.