6.6

CVE-2013-5163

Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ macOS X Version <= 10.8.5
Apple ≫ macOS X Version 10.8.0
Apple ≫ macOS X Version 10.8.1
Apple ≫ macOS X Version 10.8.2
Apple ≫ macOS X Version 10.8.3
Apple ≫ macOS X Version 10.8.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.291
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 3.9 9.2
AV:L/AC:L/Au:N/C:N/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://lists.apple.com/archives/security-announce/2013/Oct/msg00000.html
Vendor Advisory