PT-2008-4986 · Apple · Macos X
Published
2008-09-16
·
Updated
2017-08-08
·
CVE-2008-3610
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions 10.5 through 10.5.4
Description
A race condition exists in the Login Window of Apple Mac OS X. When a blank-password account is enabled, attackers can bypass password authentication. This is achieved by making multiple attempts to login to the blank-password account, followed by selecting an arbitrary account from the user list.
Recommendations
For Apple Mac OS X versions 10.5 through 10.5.4, consider disabling blank-password accounts as a temporary workaround to minimize the risk of exploitation. Restrict access to the Login Window to prevent unauthorized login attempts.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macos X