CVE-2023-42855

MEDIUM

iPadOS < 17.1 - Unauthenticated Apple ID Persistence via Physical Access

Title source: llm
STIX 2.1

Description

This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to silently persist an Apple ID on an erased device.

References (2)

Core 2

Scores

CVSS v3 4.6
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
apple/ipad_os < 17.1
apple/iphone_os < 17.1
Published Feb 21, 2024
Tracked Since Feb 18, 2026