« Volver al listado

CVE-2025-30422

Estado: ModificadaMedia (6.5)—

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-30422",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-30422",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-01T13:09:38.751434Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "AirPlay audio SDK",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.7.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "AirPlay video SDK",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.7.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-30T21:15:54.700",
  "references": [
    {
      "url": "https://support.apple.com/en-us/122403",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination."
    },
    {
      "lang": "es",
      "value": "Se solucionó un desbordamiento de búfer mejorando la validación de entrada. Este problema se solucionó en el SDK de audio de AirPlay 2.7.1, el SDK de vídeo de AirPlay 3.6.0.126 y el complemento de comunicación de CarPlay R18.1. Un atacante en la red local podría provocar el cierre inesperado de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T09:08:41.763",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BEE19EA-7BD5-441D-8C25-F2529C5AF5A5",
              "versionEndExcluding": "2.7.1"
            },
            {
              "criteria": "cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFAC8539-73DB-4545-A221-21F5E24B9AF8",
              "versionEndExcluding": "3.6.0.126"
            },
            {
              "criteria": "cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00E0D29A-8A73-4E08-9937-6574886D872D",
              "versionEndExcluding": "r18.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}