First published: Wed Mar 10 2004(Updated: )
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.2.2 | |
Apple Mac OS X Server | =10.2.4 | |
Apple Mac OS X Server | =10.2.3 | |
Apple Mac OS X Server | =10.2.5 | |
Apple Mac OS X Server | =10.2.6 | |
Apple Mac OS X Server | =10.2 | |
Apple Mac OS X Server | =10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0601 is considered a high severity vulnerability due to its potential for unauthorized account access.
CVE-2003-0601 allows remote attackers to gain unauthorized access by exploiting the failure to disable a password for a new account before it is saved.
CVE-2003-0601 affects Apple Mac OS X Server versions 10.2 through 10.2.6.
To mitigate the risk of CVE-2003-0601, ensure that accounts are configured with a strong password requirement and disable remote account creation.
Yes, Apple has provided updates that address the vulnerability present in versions of Mac OS X Server affected by CVE-2003-0601.