CVE-2008-3610

Apple Mac OS X 10.5-10.5.4 - Auth Bypass

Title source: llm

Description

Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.

Scores

EPSS 0.0026
EPSS Percentile 49.2%

Classification

CWE
CWE-287
Status draft

Affected Products (10)

apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x_server
apple/mac_os_x_server
apple/mac_os_x_server
apple/mac_os_x_server
apple/mac_os_x_server

Timeline

Published Sep 16, 2008
Tracked Since Feb 18, 2026