CVE-2009-2822
Summary
| CVE | CVE-2009-2822 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-05 16:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote attackers to bypass intended access restrictions via an 802.11 authentication frame. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Apple | Airport Base Station | All | All | All | All |
| Application | Apple | Airport Utility | 5.0 | All | All | All |
| Application | Apple | Airport Utility | 5.3.1 | All | All | All |
| Application | Apple | Airport Utility | 5.3.2 | All | All | All |
| Application | Apple | Airport Utility | 5.4.1 | All | All | All |
| Application | Apple | Airport Utility | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Apple AirPort Base Station MAC Address ACL Remote Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Apple AirPort Base Station Network Access Restriction Bypass - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Apple AirPort Base Station Lets Remote Users Access Restricted Networks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| www.osvdb.org/63420 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| APPLE-SA-2010-03-31-1 AirPort Base Station Update 2010-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About the security content of AirPort Base Station Update 2010-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.