New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 7.4
SynopsisThe remote host is affected by an authentication bypass vulnerability.
DescriptionThe remote host is affected by an authentication bypass vulnerability.
A local attacker or a remote attacker with credentials for a standard user account has the ability to blank out the root account password.
This can allow an authenticated attacker to escalate privileges to root and execute commands and read files as a system administrator.
A remote attacker without credentials can set passwords on certain disabled accounts.
Note that if this plugin is successful, Nessus has set the password on the 'nobody' account to 'nessus', and you will need to reset this password/re-disable this account to clean up.
SolutionApply Apple Security Update 2017-001.