CVE-2009-2836

Published Nov 10, 2009

Last updated 15 years ago

Overview

Description
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.
Source
cve@mitre.org
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
6.2
Impact score
10
Exploitability score
1.9
Vector string
AV:L/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-362

Evaluator

Comment
-
Impact
Per: "This issue does not affect systems prior to Mac OS X v.10.6." "A user may log in to any account without supplying a password"
Solution
Per: "This issue does not affect systems prior to Mac OS X v.10.6." "A user may log in to any account without supplying a password"

Configurations