CVE-2025-30422
Estado: ModificadaMedia (6.5)—
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.70%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-120
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-30422",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-30422",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-01T13:09:38.751434Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "Apple",
"product": "AirPlay audio SDK",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.7.1",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "AirPlay video SDK",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.7.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2025-04-30T21:15:54.700",
"references": [
{
"url": "https://support.apple.com/en-us/122403",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination."
},
{
"lang": "es",
"value": "Se solucionó un desbordamiento de búfer mejorando la validación de entrada. Este problema se solucionó en el SDK de audio de AirPlay 2.7.1, el SDK de vídeo de AirPlay 3.6.0.126 y el complemento de comunicación de CarPlay R18.1. Un atacante en la red local podría provocar el cierre inesperado de la aplicación."
}
],
"lastModified": "2026-06-17T09:08:41.763",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BEE19EA-7BD5-441D-8C25-F2529C5AF5A5",
"versionEndExcluding": "2.7.1"
},
{
"criteria": "cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFAC8539-73DB-4545-A221-21F5E24B9AF8",
"versionEndExcluding": "3.6.0.126"
},
{
"criteria": "cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00E0D29A-8A73-4E08-9937-6574886D872D",
"versionEndExcluding": "r18.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}