CVE-2010-0524: High severity Apple Mac OS X Server vulnerability
The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0524?
CVE-2010-0524 is classified as a high severity vulnerability.
How do I fix CVE-2010-0524?
To mitigate CVE-2010-0524, update your FreeRADIUS server to the latest version or modify the default configuration to restrict EAP-TLS authenticated connections.
Which versions are affected by CVE-2010-0524?
CVE-2010-0524 affects Apple Mac OS X Server versions 10.6.0, 10.6.1, and 10.6.2.
What is the impact of CVE-2010-0524?
The impact of CVE-2010-0524 allows remote attackers to gain unauthorized network access using crafted RADIUS Access Request messages.
Is there a workaround for CVE-2010-0524?
Yes, configuring the FreeRADIUS server to require specific client certificates can serve as a temporary workaround for CVE-2010-0524.