| Vulnerability Name: | CVE-2007-3184 (CCN-34807) | ||||||||
| Assigned: | 2007-06-11 | ||||||||
| Published: | 2007-06-11 | ||||||||
| Updated: | 2018-10-19 | ||||||||
| Summary: | Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation. | ||||||||
| CVSS v3 Severity: | 8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.6 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Mon Jun 11 2007 - 08:57:04 CDT Cisco Trust Agent Vulnerability Source: MITRE Type: CNA CVE-2007-3184 Source: CCN Type: SA25598 Cisco Trust Agent "User Notification" Authentication Bypass Source: SECUNIA Type: Third Party Advisory 25598 Source: SREASON Type: Exploit, Third Party Advisory 2796 Source: CCN Type: SECTRACK ID: 1018217 Cisco Trust Agent User Notification Function Lets Physically Local Users Gain Administrative Privileges Source: CISCO Type: Vendor Advisory 20070611 Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability Source: CCN Type: Cisco Web site Cisco Trust Agent Source: CCN Type: cisco-sr-20070611-cta Cisco Security Response: Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability Source: OSVDB Type: Broken Link 35340 Source: CCN Type: OSVDB ID: 35340 Cisco Trust Agent on Mac OS X User Notification Authentication Bypass Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20070611 Cisco Trust Agent Vulnerability Source: BID Type: Patch, Third Party Advisory, VDB Entry 24415 Source: CCN Type: BID-24415 Cisco Trust Agent for Mac OS X Local Privilege Escalation Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1018217 Source: VUPEN Type: Third Party Advisory ADV-2007-2140 Source: XF Type: Third Party Advisory, VDB Entry cisco-trust-unauthorized-access(34807) Source: XF Type: UNKNOWN cisco-trust-unauthorized-access(34807) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||