Current Description

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

Basic Data

PublishedMarch 03, 2003
Last ModifiedSeptember 11, 2008
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score7.5
Exploitability Score10.0
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegetrue
Obtain Other Privilegefalse

Base Metric V3

No data provided.


  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3OSAppleMac Os X10.2*******
    2.3OSAppleMac Os X10.2.1*******
    2.3OSAppleMac Os X10.2.2*******
    2.3OSAppleMac Os X10.2.3*******
    2.3OSAppleMac Os X Server10.2*******
    2.3OSAppleMac Os X Server10.2.1*******
    2.3OSAppleMac Os X Server10.2.2*******
    2.3OSAppleMac Os X Server10.2.3*******

Vulnerable Software List

Apple Mac Os X Server 10.2, 10.2.1, 10.2.2, 10.2.3
Apple Mac Os X 10.2, 10.2.1, 10.2.2, 10.2.3


NameSourceURLTags Vendor Advisory
macos-afp-unauthorized-access(11333) Advisory