CVE-2023-2489014.03.2023, 17:15Microsoft OneDrive for iOS Security Feature Bypass VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.5 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NmicrosoftCNA6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:CCVEADP------CISA-ADPADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 78%Common Weakness EnumerationCWE-1390 - Weak AuthenticationThe product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24890https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24890