CVE-2013-5143

Apple OS X Server <3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers to hijack RADIUS sessions by leveraging knowledge of the private key that matches this fallback certificate.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html

Scores

EPSS 0.0055
EPSS Percentile 43.0%

Details

Status published
Products (6)
apple/os_x_server 2.0
apple/os_x_server 2.1
apple/os_x_server 2.1.1
apple/os_x_server 2.2
apple/os_x_server 2.2.1
apple/os_x_server < 2.2.2
Published Oct 24, 2013
Tracked Since Feb 18, 2026