PT-2008-4986 · Apple · Macos X
Publicado
2008-09-16
·
Atualizado
2017-08-08
·
CVE-2008-3610
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions 10.5 through 10.5.4
Description
A race condition exists in the Login Window of Apple Mac OS X. When a blank-password account is enabled, attackers can bypass password authentication. This is achieved by making multiple attempts to login to the blank-password account, followed by selecting an arbitrary account from the user list.
Recommendations
For Apple Mac OS X versions 10.5 through 10.5.4, consider disabling blank-password accounts as a temporary workaround to minimize the risk of exploitation. Restrict access to the Login Window to prevent unauthorized login attempts.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Macos X