PT-2022-16971 · Apple · Gamecenter

Mtrezzapublished

+1

·

Published

2022-05-04

·

Updated

2024-03-06

·

CVE-2022-24901

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apple Game Center (affected versions not specified)
Description The issue arises from improper validation of the Apple certificate URL in the Apple Game Center authentication adapter, allowing attackers to bypass authentication. This makes the server vulnerable to Denial of Service (DoS) attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-PARSE-2022-24901
CVE-2022-24901
GHSA-QF8X-VQJV-92GR

Affected Products

Gamecenter