ID

VAR-200403-0088


CVE

CVE-2003-0601


TITLE

Apple Mac OS X Server Workgroup Manager Unsafe account creation vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200403-124

DESCRIPTION

Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved. It has been reported the OS X Server Workgroup Manager may create accounts in an insecure manner. This vulnerability may allow an attacker to gain unauthorized access or elevated privileges to an affected system via the newly created account. Mac OS X is an operating system used on Mac machines, based on the BSD system. However, no detailed vulnerability details have been provided so far

Trust: 1.35

sources: NVD: CVE-2003-0601 // BID: 8266 // VULHUB: VHN-7429 // VULMON: CVE-2003-0601

AFFECTED PRODUCTS

vendor:applemodel:mac os x serverscope:eqversion:10.2.6

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.5

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.1

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.4

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.2

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.3

Trust: 1.6

vendor:applemodel:mac os serverscope:eqversion:x10.2.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2

Trust: 0.3

sources: BID: 8266 // CNNVD: CNNVD-200403-124 // NVD: CVE-2003-0601

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0601
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200403-124
value: HIGH

Trust: 0.6

VULHUB: VHN-7429
value: HIGH

Trust: 0.1

VULMON: CVE-2003-0601
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2003-0601
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-7429
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-7429 // VULMON: CVE-2003-0601 // CNNVD: CNNVD-200403-124 // NVD: CVE-2003-0601

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0601

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200403-124

TYPE

Unknown

Trust: 0.9

sources: BID: 8266 // CNNVD: CNNVD-200403-124

EXTERNAL IDS

db:NVDid:CVE-2003-0601

Trust: 2.1

db:BIDid:8266

Trust: 2.1

db:XFid:12728

Trust: 0.6

db:CNNVDid:CNNVD-200403-124

Trust: 0.6

db:VULHUBid:VHN-7429

Trust: 0.1

db:VULMONid:CVE-2003-0601

Trust: 0.1

sources: VULHUB: VHN-7429 // VULMON: CVE-2003-0601 // BID: 8266 // CNNVD: CNNVD-200403-124 // NVD: CVE-2003-0601

REFERENCES

url:http://www.securityfocus.com/bid/8266

Trust: 1.9

url:http://docs.info.apple.com/article.html?artnum=25631

Trust: 1.8

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/12728

Trust: 1.2

url:http://xforce.iss.net/xforce/xfdb/12728

Trust: 0.6

url:http://docs.info.apple.com/article.html?artnum=61798

Trust: 0.3

url:http://docs.info.apple.com/article.html?artnum=120235

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-7429 // VULMON: CVE-2003-0601 // BID: 8266 // CNNVD: CNNVD-200403-124 // NVD: CVE-2003-0601

CREDITS

Apple Security Updates

Trust: 0.6

sources: CNNVD: CNNVD-200403-124

SOURCES

db:VULHUBid:VHN-7429
db:VULMONid:CVE-2003-0601
db:BIDid:8266
db:CNNVDid:CNNVD-200403-124
db:NVDid:CVE-2003-0601

LAST UPDATE DATE

2025-04-03T22:31:40.574000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-7429date:2017-07-11T00:00:00
db:VULMONid:CVE-2003-0601date:2017-07-11T00:00:00
db:BIDid:8266date:2009-07-11T22:56:00
db:CNNVDid:CNNVD-200403-124date:2005-10-20T00:00:00
db:NVDid:CVE-2003-0601date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-7429date:2004-03-29T00:00:00
db:VULMONid:CVE-2003-0601date:2004-03-29T00:00:00
db:BIDid:8266date:2003-07-24T00:00:00
db:CNNVDid:CNNVD-200403-124date:2003-07-23T00:00:00
db:NVDid:CVE-2003-0601date:2004-03-29T05:00:00