CVE-2008-3610

UnknownEPSS 2.04%

Last modified

CVE-2008-3610 is a vulnerability of currently unknown severity. Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.. EPSS estimates a 2.04% chance of exploitation in the next 30 days.

Description

Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.

Metrics

EPSS Probability
2.04%

78.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AppleMac Os X10.5
AppleMac Os X10.5.1
AppleMac Os X10.5.2
AppleMac Os X10.5.3
AppleMac Os X10.5.4
AppleMac Os X Server10.5
AppleMac Os X Server10.5.1
AppleMac Os X Server10.5.2
AppleMac Os X Server10.5.3
AppleMac Os X Server10.5.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-3610?
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
How severe is CVE-2008-3610?
Severity scoring for CVE-2008-3610 is pending analysis. The EPSS model estimates a 2.04% probability of exploitation in the next 30 days.
How do I fix CVE-2008-3610?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-3610?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST