« Volver al listado

CVE-2024-27855

Estado: ModificadaAlta (8.8)—

El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 y iPadOS 17.5, iOS 16.7.8 y iPadOS 16.7.8. Un acceso directo puede utilizar datos confidenciales con determinadas acciones sin avisar al usuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-27855",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-27855",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-16T15:15:40.289639Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "16.7.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.5",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "13.6.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14.5",
              "versionType": "custom"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:iphone:*"
          ],
          "vendor": "apple",
          "product": "iphone_os",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "16.7.8",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "ipad_os",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "16.7.8",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:macos:13.0:*:*:*:*:*:*:*",
            "cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "macos",
          "versions": [
            {
              "status": "affected",
              "version": "13.0",
              "lessThan": "13.6.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-06-10T21:15:51.753",
  "references": [
    {
      "url": "https://support.apple.com/en-us/120898",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120900",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120903",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120905",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT214100",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214106",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214107",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214100",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214106",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214107",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without prompting the user."
    },
    {
      "lang": "es",
      "value": "El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 y iPadOS 17.5, iOS 16.7.8 y iPadOS 16.7.8. Un acceso directo puede utilizar datos confidenciales con determinadas acciones sin avisar al usuario."
    }
  ],
  "lastModified": "2026-06-17T07:20:27.787",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "732206AE-D798-41FB-8D91-F796820F912D",
              "versionEndExcluding": "16.7.8"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C520138-1984-4369-8615-09FF57F0BB70",
              "versionEndExcluding": "17.5",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EDF6AF0-A238-47E5-9A9D-F6FDB832DD8C",
              "versionEndExcluding": "16.7.8"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEC0ACF3-F486-4536-8415-A176C68CE183",
              "versionEndExcluding": "17.5",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C456020E-3025-4728-9F77-C1E44E6B0EA7",
              "versionEndExcluding": "13.6.7"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AB18623-7D06-4946-99FC-808A4A913ED9",
              "versionEndExcluding": "14.5",
              "versionStartIncluding": "14.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}