CVE Vulnerabilities

CVE-2022-22656

Improper Authentication

Published: Mar 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple10.15 (including)10.15.7 (excluding)
Mac_os_xApple10.15.7-security_update_2022-001 (including)10.15.7-security_update_2022-001 (including)
Mac_os_xApple10.15.7-security_update_2022-002 (including)10.15.7-security_update_2022-002 (including)
MacosApple11.6 (including)11.6.5 (excluding)
MacosApple12.0 (including)12.3 (excluding)
MacosApple10.15.7 (including)10.15.7 (including)

Potential Mitigations

References