Vulnerability Name: | CVE-2010-0512 (CCN-57283) | ||||||||
Assigned: | 2010-03-29 | ||||||||
Published: | 2010-03-29 | ||||||||
Updated: | 2010-05-21 | ||||||||
Summary: | The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials. Per: http://support.apple.com/kb/HT4077 'This issue only affects systems configured to use a network account server, and does not affect systems prior to Mac OS X v10.6.' | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0512 Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2010-03-29-1 Source: CCN Type: SA39158 Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: CCN Type: Apple Web site About the security content of Security Update 2010-002 / Mac OS X v10.6.3 Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT4077 Source: CCN Type: OSVDB ID: 63379 Apple Mac OS X Preferences Unspecified System Login Restriction Bypass Source: CCN Type: BID-39020 RETIRED: Apple Mac OS X APPLE-SA-2010-03-29-1 Multiple Security Vulnerabilities Source: BID Type: UNKNOWN 39153 Source: CCN Type: BID-39153 Apple Mac OS X Preferences System Login Restrictions Authentication Bypass Security Vulnerability Source: XF Type: UNKNOWN macosx-preferences-login-sec-bypass(57283) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |