« Volver al listado

CVE-2021-30889

Estado: ModificadaAlta (8.8)—

Se abordó un problema de desbordamiento del búfer con un manejo de memoria mejorada. Este problema se corrigió en macOS Monterey versión 12.0.1, iOS versión 15.1 y iPadOS versión 15.1, watchOS versión 8.1, tvOS versión 15.1. El procesamiento de contenido web maliciosamente diseñado puede conllevar a una ejecución de código arbitrario

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-30889",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "15.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "12.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "8.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "15.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-24T19:15:16.957",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/12/20/6",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212867",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212869",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212874",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212876",
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2021/12/20/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212867",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212869",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212874",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212876",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "Se abordó un problema de desbordamiento del búfer con un manejo de memoria mejorada. Este problema se corrigió en macOS Monterey versión 12.0.1, iOS versión 15.1 y iPadOS versión 15.1, watchOS versión 8.1, tvOS versión 15.1. El procesamiento de contenido web maliciosamente diseñado puede conllevar a una ejecución de código arbitrario"
    }
  ],
  "lastModified": "2026-06-17T03:51:05.153",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B93FE038-6BF4-484E-8BBC-6F4332DCE045",
              "versionEndExcluding": "15.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E11B095-8786-478A-A6BA-82DED207426B",
              "versionEndExcluding": "15.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "579B2A0D-A84F-45C2-B545-35ECEA3297DA",
              "versionEndExcluding": "12.0.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A76BB8B-613D-46B7-80F8-83B6EF76F344",
              "versionEndExcluding": "15.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A82F66E5-A6BF-4D7A-8DCA-DD4C35723936",
              "versionEndExcluding": "8.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}