CVE-2005-1332
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=301381Vendor Advisory
- http://lists.apple.com/archives/security-announce/2005/May/msg00001.htmlVendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt
- http://www.kb.cert.org/vuls/id/258390US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-136A.htmlUS Government Resource
- http://docs.info.apple.com/article.html?artnum=301381Vendor Advisory
- http://lists.apple.com/archives/security-announce/2005/May/msg00001.htmlVendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt
- http://www.kb.cert.org/vuls/id/258390US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-136A.htmlUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.