« Volver al listado

CVE-2017-2428

Estado: ModificadaCrítica (9.8)—

Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.3 está afectado. macOS en versiones anteriores a 10.12.4 está afectado. tvOS en versiones anteriores a 10.2 está afectado. watchOS en versiones anteriores a 3.2 está afectado. El problema involucra nghttp2 en versiones anteriores a 1.17.0 en el componente "HTTPProtocol". Esto permite a servidores remotos HTTP/2 tener un impacto no especificado a través de vectores desconocidos.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2428",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-02T01:59:01.810",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97146",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1038138",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://github.com/nghttp2/nghttp2/releases/tag/v1.17.0",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT207601",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT207602",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT207615",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT207617",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/97146",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1038138",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/nghttp2/nghttp2/releases/tag/v1.17.0",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/HT207601",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/HT207602",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/HT207615",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/HT207617",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves nghttp2 before 1.17.0 in the \"HTTPProtocol\" component. It allows remote HTTP/2 servers to have an unspecified impact via unknown vectors."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.3 está afectado. macOS en versiones anteriores a 10.12.4 está afectado. tvOS en versiones anteriores a 10.2 está afectado. watchOS en versiones anteriores a 3.2 está afectado. El problema involucra nghttp2 en versiones anteriores a 1.17.0 en el componente \"HTTPProtocol\". Esto permite a servidores remotos HTTP/2 tener un impacto no especificado a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-17T01:16:10.963",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A705829E-76A8-4AA8-8D82-037E4E8A52FC",
              "versionEndIncluding": "10.2.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1684E315-F3D0-4D2B-83D1-41E004FBFA70",
              "versionEndIncluding": "10.12.3"
            },
            {
              "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "197AACC5-2587-46F6-8658-1B4824B42580",
              "versionEndIncluding": "10.1.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "395A9BA0-9375-4902-AA7B-6D2A153E7E0C",
              "versionEndIncluding": "3.1.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}