Apple · Workgroup Manager · CVE-2006-4399
**Name of the Vulnerable Software and Affected Versions**
Apple Mac OS X versions 10.4 through 10.4.7
**Description**
The issue is related to an inconsistency in the Workgroup Manager user interface, which may lead to less secure password management. Administrators may be allowed to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, even though this operation is not supported.
**Recommendations**
For Apple Mac OS X versions 10.4 through 10.4.7, avoid using the Workgroup Manager to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, as this operation is not actually supported and may result in less secure password management.