Vulnerability Name: | CVE-2003-0242 (CCN-12027) | ||||||||
Assigned: | 2003-05-19 | ||||||||
Published: | 2003-05-19 | ||||||||
Updated: | 2020-12-09 | ||||||||
Summary: | IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2003-0242 Source: CCN Type: AppleCare Knowledge Base Document 61798 Apple Security Updates Source: CONFIRM Type: Broken Link http://docs.info.apple.com/article.html?artnum=61798 Source: CCN Type: SA8798 Apple Mac OS X IPSec ACL Bypass Source: SECUNIA Type: Third Party Advisory 8798 Source: CCN Type: SECTRACK ID: 1006796 Mac OS X IPSec Policy Flaw May Remote Users Bypass Access Controls Source: SECTRACK Type: Third Party Advisory, VDB Entry 1006796 Source: CCN Type: US-CERT VU#869548 Apple Mac OS X IPSec mechanism fails to handle certain incoming security policies that match by port Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#869548 Source: CCN Type: OSVDB ID: 6545 Apple Mac OS X IPSec Port Rule Policy Bypass Source: BID Type: Third Party Advisory, VDB Entry 7628 Source: CCN Type: BID-7628 Apple MacOS X IPSec Policy By Port Bypass Vulnerability Source: XF Type: Third Party Advisory, VDB Entry macos-ipsec-acl-bypass(12027) Source: XF Type: UNKNOWN macos-ipsec-acl-bypass(12027) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |