Vulnerability Name: | CVE-2012-0652 (CCN-75424) | ||||||||
Assigned: | 2012-05-07 | ||||||||
Published: | 2012-05-07 | ||||||||
Updated: | 2017-12-05 | ||||||||
Summary: | Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-0652 Source: APPLE Type: Vendor Advisory APPLE-SA-2012-05-09-1 Source: APPLE Type: UNKNOWN APPLE-SA-2012-09-19-2 Source: CCN Type: SA49039 Apple Mac OS X FileVault Plain Text Password Logging Security Issue Source: CCN Type: Apple Web site About the security content of OS X Lion v10.7.4 and Security Update 2012-002 Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT5281 Source: CCN Type: Apple KB HT5501 About the security content of OS X Mountain Lion v10.8.2, OS X Lion v10.7.5 and Security Update 2012-004 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT5501 Source: CCN Type: OSVDB ID: 82016 Apple Mac OS X FileVault secure.log Plaintext Local Password Disclosure Source: CCN Type: BID-53402 Apple Mac OS X FileVault Plain Text Password Local Security Bypass Vulnerability Source: BID Type: UNKNOWN 53445 Source: CCN Type: BID-53445 RETIRED: Apple Mac OS X Security Update 2012-002 Multiple Security Vulnerabilities Source: BID Type: UNKNOWN 53457 Source: CCN Type: BID-53457 Apple Mac OS X CVE-2012-0652 Local Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1027024 Source: CCN Type: Apple Support Communities Network user: plain text PWs in client log?! Source: XF Type: UNKNOWN macos-filevault-info-disclosure(75424) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |