CVE-1999-1543: Weak Encryption
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the macOS Users & Groups Data File: tighten filesystem permissions on the file, limit which administrative accounts can read it, and audit/monitor access to the file to reduce exposure.
- Operational
Assume passwords stored in the Users & Groups Data File may be exposed and rotate/replace those passwords (and any credentials derived from them) for affected accounts.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1543?
CVE-1999-1543 is considered to have a moderate severity due to the weak encryption of passwords.
How do I fix CVE-1999-1543?
To fix CVE-1999-1543, users should upgrade to a later version of macOS that uses stronger encryption methods for password storage.
What versions of macOS are affected by CVE-1999-1543?
CVE-1999-1543 affects macOS versions 7.5.3 through 8.6.
What are the potential risks associated with CVE-1999-1543?
The main risk associated with CVE-1999-1543 is that weakly encrypted passwords can be easily compromised by an attacker.
Is CVE-1999-1543 still a relevant concern today?
Although CVE-1999-1543 is an older vulnerability, it remains a reminder of the importance of using strong encryption for sensitive data.