PT-2008-4986 · Apple · Macos X

Published

2008-09-16

·

Updated

2017-08-08

·

CVE-2008-3610

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple Mac OS X versions 10.5 through 10.5.4
Description A race condition exists in the Login Window of Apple Mac OS X. When a blank-password account is enabled, attackers can bypass password authentication. This is achieved by making multiple attempts to login to the blank-password account, followed by selecting an arbitrary account from the user list.
Recommendations For Apple Mac OS X versions 10.5 through 10.5.4, consider disabling blank-password accounts as a temporary workaround to minimize the risk of exploitation. Restrict access to the Login Window to prevent unauthorized login attempts.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3610

Affected Products

Macos X