CVE-2023-40451
Estado: ModificadaAlta (8.8)—
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.08%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- http://seclists.org/fulldisclosure/2023/Oct/2
- http://www.openwall.com/lists/oss-security/2023/09/28/3
- https://security.gentoo.org/glsa/202401-33
- https://support.apple.com/en-us/HT213941
- http://seclists.org/fulldisclosure/2023/Oct/2
- http://www.openwall.com/lists/oss-security/2023/09/28/3
- https://security.gentoo.org/glsa/202401-33
- https://support.apple.com/en-us/HT213941
- https://webkitgtk.org/security/WSA-2023-0009.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-40451",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-40451",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-01T19:54:23.789025Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "Apple",
"product": "Safari",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "17",
"versionType": "custom"
}
]
}
]
}
],
"published": "2023-09-27T15:19:17.090",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2023/Oct/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2023/09/28/3",
"tags": [
"Mailing List"
],
"source": "product-security@apple.com"
},
{
"url": "https://security.gentoo.org/glsa/202401-33",
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/en-us/HT213941",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://seclists.org/fulldisclosure/2023/Oct/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2023/09/28/3",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/202401-33",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/en-us/HT213941",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://webkitgtk.org/security/WSA-2023-0009.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code."
},
{
"lang": "es",
"value": "Este problema se solucionó mejorando la aplicación de la sandbox de iframe. Este problema se solucionó en Safari 17. Un atacante con ejecución de JavaScript puede ejecutar código arbitrario."
}
],
"lastModified": "2026-06-17T06:17:54.477",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93FB6D0F-A668-47CF-A63D-755CA3BA259A",
"versionEndExcluding": "17.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}