{"api_version":"1","generated_at":"2026-07-23T09:40:28+00:00","cve":"CVE-2008-3611","urls":{"html":"https://cve.report/CVE-2008-3611","api":"https://cve.report/api/cve/CVE-2008-3611.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3611","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3611"},"summary":{"title":"CVE-2008-3611","description":"Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-16 23:00:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.3","severity":"","vector":"AV:L/AC:M/Au:N/C:N/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:C/A:C","baseScore":6.3,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html","name":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2008-09-15 Mac OS X v10.5.5 and Security Update 2008-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31189","name":"http://www.securityfocus.com/bid/31189","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Apple Mac OS X 2008-006 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1020878","name":"http://securitytracker.com/id?1020878","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Login Window Password Change Bug Lets Local User Access the System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2584","name":"http://www.vupen.com/english/advisories/2008/2584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45171","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-260A -- Apple Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31882","name":"http://secunia.com/advisories/31882","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3611","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3611","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3611","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.4.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3611","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.4.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:18.935Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"31189","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31189"},{"name":"APPLE-SA-2008-09-15","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"1020878","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1020878"},{"name":"ADV-2008-2584","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"31882","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31882"},{"name":"macos-loginscreen-security-bypass(45171)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45171"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"31189","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31189"},{"name":"APPLE-SA-2008-09-15","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"1020878","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1020878"},{"name":"ADV-2008-2584","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"31882","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31882"},{"name":"macos-loginscreen-security-bypass(45171)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45171"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3611","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"31189","refsource":"BID","url":"http://www.securityfocus.com/bid/31189"},{"name":"APPLE-SA-2008-09-15","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"1020878","refsource":"SECTRACK","url":"http://securitytracker.com/id?1020878"},{"name":"ADV-2008-2584","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"31882","refsource":"SECUNIA","url":"http://secunia.com/advisories/31882"},{"name":"macos-loginscreen-security-bypass(45171)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45171"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3611","datePublished":"2008-09-16T23:00:00.000Z","dateReserved":"2008-08-12T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:18.935Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-16 23:00:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:C/A:C","baseScore":6.3,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":9.2,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*","matchCriteriaId":"6EE39585-CF3B-4493-96D8-B394544C7643"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*","matchCriteriaId":"D09D5933-A7D9-4A61-B863-CD8E7D5E67D8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3611","Ordinal":"1","Title":"CVE-2008-3611","CVE":"CVE-2008-3611","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3611","Ordinal":"1","NoteData":"Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.","Type":"Description","Title":"CVE-2008-3611"},{"CveYear":"2008","CveId":"3611","Ordinal":"2","NoteData":"2008-09-16","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3611","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}