Unrated severityNVD Advisory· Published Sep 16, 2008· Updated Apr 23, 2026
CVE-2008-3611
CVE-2008-3611
Description
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
Affected products
2- cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/31189nvdPatch
- secunia.com/advisories/31882nvdVendor Advisory
- www.vupen.com/english/advisories/2008/2584nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA08-260A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce//2008/Sep/msg00005.htmlnvd
- securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45171nvd
News mentions
0No linked articles in our index yet.