CVE-2023-28202
MEDIUMApple Ipados < 16.5 - Password Reset Weakness
Title source: ruleDescription
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app firewall setting may not take effect after exiting the Settings app.
References (4)
Scores
CVSS v3
5.5
EPSS
0.0003
EPSS Percentile
6.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-640
Status
published
Affected Products (5)
apple/ipados
< 16.5
apple/iphone_os
< 16.5
apple/macos
< 13.4
apple/tvos
< 16.5
apple/watchos
< 9.5
Timeline
Published
Jun 23, 2023
Tracked Since
Feb 18, 2026