CVE-2005-2504: High severity Apple Mac OS X Server vulnerability
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2504?
CVE-2005-2504 is classified as a moderate severity vulnerability due to potential user confusion regarding Bluetooth security settings.
How does CVE-2005-2504 affect Bluetooth devices?
CVE-2005-2504 affects Bluetooth devices on Mac OS X 10.4.2 by incorrectly indicating that authentication is not required when it actually is.
What is the impact of CVE-2005-2504 on user security?
The impact of CVE-2005-2504 may lead users to believe their Bluetooth devices are secure when they are not, potentially allowing unauthorized access.
How can I mitigate CVE-2005-2504?
To mitigate CVE-2005-2504, users should verify Bluetooth settings manually and ensure pairing is enforced for security.
Is there a fix for CVE-2005-2504?
Yes, updating to a later version of Mac OS X that addresses this flaw will fix CVE-2005-2504.