{"api_version":"1","generated_at":"2026-07-23T11:15:12+00:00","cve":"CVE-2010-0512","urls":{"html":"https://cve.report/CVE-2010-0512","api":"https://cve.report/api/cve/CVE-2010-0512.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0512","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0512"},"summary":{"title":"CVE-2010-0512","description":"The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.","state":"PUBLISHED","assigner":"apple","published_at":"2010-03-30 18:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4077","name":"http://support.apple.com/kb/HT4077","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About the security content of Security Update 2010-002 / Mac OS X v10.6.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/39153","name":"http://www.securityfocus.com/bid/39153","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X Preferences System Login Restrictions Authentication Bypass Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0512","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0512","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"512","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:52:19.211Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"39153","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/39153"},{"name":"APPLE-SA-2010-03-29-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4077"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-04-30T09:00:00.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"39153","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/39153"},{"name":"APPLE-SA-2010-03-29-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4077"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2010-0512","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"39153","refsource":"BID","url":"http://www.securityfocus.com/bid/39153"},{"name":"APPLE-SA-2010-03-29-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html"},{"name":"http://support.apple.com/kb/HT4077","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4077"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2010-0512","datePublished":"2010-03-30T18:00:00.000Z","dateReserved":"2010-02-03T00:00:00.000Z","dateUpdated":"2024-08-07T00:52:19.211Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-30 18:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.0:*:*:*:*:*:*:*","matchCriteriaId":"3C69DEE9-3FA5-408E-AD27-F5E7043F852A"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*","matchCriteriaId":"D25D1FD3-C291-492C-83A7-0AFAFAADC98D"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*","matchCriteriaId":"5B565F77-C310-4B83-B098-22F9489C226C"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.0:*:*:*:*:*:*:*","matchCriteriaId":"26E34E35-CCE9-42BE-9AFF-561D8AA90E25"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*","matchCriteriaId":"A04FF6EE-D4DA-4D70-B0CE-154292828531"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*","matchCriteriaId":"9425320F-D119-49EB-9265-3159070DFE93"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"512","Ordinal":"1","Title":"CVE-2010-0512","CVE":"CVE-2010-0512","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"512","Ordinal":"1","NoteData":"The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.","Type":"Description","Title":"CVE-2010-0512"},{"CveYear":"2010","CveId":"512","Ordinal":"2","NoteData":"2010-03-30","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"512","Ordinal":"3","NoteData":"2010-04-30","Type":"Other","Title":"Modified"}]}}}