{"api_version":"1","generated_at":"2026-07-23T07:10:35+00:00","cve":"CVE-2007-3184","urls":{"html":"https://cve.report/CVE-2007-3184","api":"https://cve.report/api/cve/CVE-2007-3184.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3184","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3184"},"summary":{"title":"CVE-2007-3184","description":"Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-12 21:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2140","name":"http://www.vupen.com/english/advisories/2007/2140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html","name":"http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Security Response: Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25598","name":"http://secunia.com/advisories/25598","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Cisco Trust Agent \"User Notification\" Authentication Bypass - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24415","name":"http://www.securityfocus.com/bid/24415","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"Cisco Trust Agent for Mac OS X Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34807","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34807","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/2796","name":"http://securityreason.com/securityalert/2796","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"Cisco Trust Agent  Vulnerability - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/35340","name":"http://www.osvdb.org/35340","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1018217","name":"http://www.securitytracker.com/id?1018217","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Cisco Trust Agent User Notification Function Lets Physically Local Users Gain Administrative Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/471041/100/0/threaded","name":"http://www.securityfocus.com/archive/1/471041/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3184","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3184","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3184","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3184","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"trust_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:05:29.200Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35340","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/35340"},{"name":"20070611 Cisco Trust Agent Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471041/100/0/threaded"},{"name":"1018217","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018217"},{"name":"2796","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2796"},{"name":"20070611 Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html"},{"name":"25598","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25598"},{"name":"24415","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24415"},{"name":"cisco-trust-unauthorized-access(34807)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34807"},{"name":"ADV-2007-2140","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2140"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35340","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/35340"},{"name":"20070611 Cisco Trust Agent Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/471041/100/0/threaded"},{"name":"1018217","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018217"},{"name":"2796","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2796"},{"name":"20070611 Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html"},{"name":"25598","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25598"},{"name":"24415","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24415"},{"name":"cisco-trust-unauthorized-access(34807)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34807"},{"name":"ADV-2007-2140","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2140"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3184","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35340","refsource":"OSVDB","url":"http://www.osvdb.org/35340"},{"name":"20070611 Cisco Trust Agent Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/471041/100/0/threaded"},{"name":"1018217","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018217"},{"name":"2796","refsource":"SREASON","url":"http://securityreason.com/securityalert/2796"},{"name":"20070611 Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability","refsource":"CISCO","url":"http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html"},{"name":"25598","refsource":"SECUNIA","url":"http://secunia.com/advisories/25598"},{"name":"24415","refsource":"BID","url":"http://www.securityfocus.com/bid/24415"},{"name":"cisco-trust-unauthorized-access(34807)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34807"},{"name":"ADV-2007-2140","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2140"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3184","datePublished":"2007-06-12T21:00:00.000Z","dateReserved":"2007-06-12T00:00:00.000Z","dateUpdated":"2024-08-07T14:05:29.200Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-12 21:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:cisco:trust_agent:*:*:*:*:*:*:*:*","versionEndExcluding":"2.1.104.0","matchCriteriaId":"527400A7-5CC9-4B43-B0C1-60FBC7795E37"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","matchCriteriaId":"0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3184","Ordinal":"1","Title":"CVE-2007-3184","CVE":"CVE-2007-3184","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3184","Ordinal":"1","NoteData":"Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.","Type":"Description","Title":"CVE-2007-3184"},{"CveYear":"2007","CveId":"3184","Ordinal":"2","NoteData":"2007-06-12","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3184","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}