CVE-2003-0601: High severity Apple Mac OS X Server vulnerability
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0601?
CVE-2003-0601 is considered a high severity vulnerability due to its potential for unauthorized account access.
How does CVE-2003-0601 exploit a flaw in Apple Mac OS X Server?
CVE-2003-0601 allows remote attackers to gain unauthorized access by exploiting the failure to disable a password for a new account before it is saved.
What versions of Apple Mac OS X Server are affected by CVE-2003-0601?
CVE-2003-0601 affects Apple Mac OS X Server versions 10.2 through 10.2.6.
How can I mitigate the risk associated with CVE-2003-0601?
To mitigate the risk of CVE-2003-0601, ensure that accounts are configured with a strong password requirement and disable remote account creation.
Is there a patch available for CVE-2003-0601?
Yes, Apple has provided updates that address the vulnerability present in versions of Mac OS X Server affected by CVE-2003-0601.