CVE-2025-24200

MEDIUM(6.1)KEV

Apple iOS and iPadOS Incorrect Authorization Vulnerability

Beschreibung

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

KEV-Informationen

Hersteller
Apple
Produkt
iOS and iPadOS
Hinzugefügt am
12. Februar 2025
Fälligkeitsdatum
5. März 2025
Erforderliche Maßnahme
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NIm Rechner öffnen
Angriffsvektor
PHYSICAL
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
NONE
Ausnutzbarkeitsscore
0.9
Auswirkungsscore
5.2

CWEs

Betroffene Produkte

HerstellerProduktVersion
appleipados< 15.8.4; >= 16.0, < 16.7.11; >= 17.0, <= 17.7.5; >= 18.0, < 18.3.1
appleiphone os< 15.8.4; >= 16.0, < 16.7.11; >= 17.0, < 18.3.1

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
6.1
MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.1
MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Referenzen

CVSS-Score

6.1
MEDIUM(6.1)

EPSS-Score

EPSS-Score4.37%
EPSS-Perzentil90.3%

Daten

Veröffentlicht10. Februar 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.