CVE Vulnerabilities

CVE-2023-23493

Improper Authentication

Published: Feb 27, 2023 | Modified: Mar 08, 2023
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Macos Apple 12.0.0 (including) 12.6.3 (excluding)
Macos Apple 13.0 (including) 13.2 (excluding)

Potential Mitigations

References