CVE-2003-0601
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=25631Patch, Vendor Advisory
- http://www.securityfocus.com/bid/8266Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12728
- http://docs.info.apple.com/article.html?artnum=25631Patch, Vendor Advisory
- http://www.securityfocus.com/bid/8266Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12728
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.