Vulnerabilities > CVE-2021-30874 - Missing Authorization vulnerability in Apple Ipados and Iphone OS

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
apple
CWE-862

Summary

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.

Vulnerable Configurations

Part Description Count
OS
Apple
307

Common Weakness Enumeration (CWE)