First published: Fri Aug 19 2005(Updated: )
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.4.2 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2504 is classified as a moderate severity vulnerability due to potential user confusion regarding Bluetooth security settings.
CVE-2005-2504 affects Bluetooth devices on Mac OS X 10.4.2 by incorrectly indicating that authentication is not required when it actually is.
The impact of CVE-2005-2504 may lead users to believe their Bluetooth devices are secure when they are not, potentially allowing unauthorized access.
To mitigate CVE-2005-2504, users should verify Bluetooth settings manually and ensure pairing is enforced for security.
Yes, updating to a later version of Mac OS X that addresses this flaw will fix CVE-2005-2504.