First published: Tue Jun 12 2007(Updated: )
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Trust Agent | <2.1.104.0 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3184 is considered a moderate severity vulnerability due to its potential for unauthorized access with physical access to the affected system.
To fix CVE-2007-3184, update Cisco Trust Agent to version 2.1.104.0 or later, ensuring your MacOS X is also updated to a secure version.
CVE-2007-3184 affects users of Cisco Trust Agent running on MacOS X versions prior to Yosemite with older releases of the software.
If vulnerable to CVE-2007-3184, an attacker with physical access can bypass authentication and modify system settings, including passwords.
There are no known effective workarounds for CVE-2007-3184, and the recommended solution is to apply the update.