CVE-2017-2488: High severity apple remote desktop vulnerability
A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.
Other sources
Authentication. A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2488?
CVE-2017-2488 is rated as a medium severity vulnerability due to its impact on password security.
How do I fix CVE-2017-2488?
To fix CVE-2017-2488, you should update to Apple Remote Desktop version 3.9 or later.
What type of vulnerability is CVE-2017-2488?
CVE-2017-2488 is a cryptographic vulnerability in the authentication protocol used by Remote Desktop.
Which versions of Apple Remote Desktop are affected by CVE-2017-2488?
Apple Remote Desktop versions prior to 3.9 are affected by CVE-2017-2488.
What kind of attack can be performed due to CVE-2017-2488?
An attacker exploiting CVE-2017-2488 may be able to capture cleartext passwords during the authentication process.