Cyber Resilience

CVE-2023-42855

Apple Ipad Os ≤ 17.1

Published
21 February 2024
Modified
04 November 2025
Patch / advisory
CVSS Score v3.1 4.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0023 14th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2023-42855 is a medium-severity an unspecified weakness vulnerability in Apple Ipad Os. Its CVSS base score is 4.6 (Medium).

Operationally, ranked at the 14th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to silently persist an Apple ID on an erased device.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-23240Same product: Apple Ipad Os
CVE-2023-42928Same product: Apple Ipad Os
CVE-2023-42951Same product: Apple Ipad Os
CVE-2024-23243Same product: Apple Ipad Os
CVE-2024-44139Same product: Apple Ipad Os
CVE-2024-23256Same product: Apple Ipad Os
CVE-2023-42939Same product: Apple Ipad Os
CVE-2024-23242Same product: Apple Ipad Os
CVE-2023-42977Same product: Apple Ipad Os
CVE-2024-23255Same product: Apple Ipad Os

Affected Assets

apple
ipad os
≤ 17.1
apple
iphone os
≤ 17.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References