CVE Vulnerabilities

CVE-2014-4425

Improper Authentication

Published: Oct 18, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

CFPreferences in Apple OS X before 10.10 does not properly enforce the require password after sleep or screen saver begins setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple * 10.9.5 (including)

Potential Mitigations

References