The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-03-30 11:30
Updated : 2010-05-20 22:57
NVD link : CVE-2010-0524
Mitre link : CVE-2010-0524
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
apple
- mac_os_x
- mac_os_x_server