CVE-2007-3184
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- apple/mac os x
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/25598Third Party Advisory
- http://securityreason.com/securityalert/2796Exploit, Third Party Advisory
- http://www.cisco.com/en/US/products/products_security_response09186a008085d645.htmlVendor Advisory
- http://www.osvdb.org/35340Broken Link
- http://www.securityfocus.com/archive/1/471041/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24415Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018217Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2140Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34807Third Party Advisory, VDB Entry
- http://secunia.com/advisories/25598Third Party Advisory
- http://securityreason.com/securityalert/2796Exploit, Third Party Advisory
- http://www.cisco.com/en/US/products/products_security_response09186a008085d645.htmlVendor Advisory
- http://www.osvdb.org/35340Broken Link
- http://www.securityfocus.com/archive/1/471041/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24415Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018217Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2140Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34807Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.