CVE-2009-0138: Critical severity Apple iOS and macOS vulnerability
servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to servermgrd (Server Manager) on systems running Mac OS X 10.5.6. For example, block incoming connections to the servermgrd service or allow access only from trusted management IPs via firewall/ACLs.
- Operational
Audit systems running Mac OS X 10.5.6 for unauthorized or unexpected system configuration changes and review relevant logs for remote access to servermgrd.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0138?
CVE-2009-0138 has a high severity rating due to its potential for remote exploitation and unauthorized system changes.
How do I fix CVE-2009-0138?
To fix CVE-2009-0138, update your Apple Mac OS X to a version that addresses this vulnerability.
What types of systems are affected by CVE-2009-0138?
CVE-2009-0138 affects Apple Mac OS X 10.5.6 and Apple Mac OS X Server 10.5.6.
What kind of attacks can be executed using CVE-2009-0138?
Exploiting CVE-2009-0138 allows attackers to modify the system configuration remotely.
Is CVE-2009-0138 a local or remote vulnerability?
CVE-2009-0138 is a remote vulnerability that can be exploited over a network.