macOS 10.13 Authentication Bypass Remote Check (CVE-2017-13872)

High Nessus Plugin ID 105003


The remote host is affected by an authentication bypass vulnerability.


The remote host is affected by an authentication bypass vulnerability.
A local attacker or a remote attacker with credentials for a standard user account has the ability to blank out the root account password.
This can allow an authenticated attacker to escalate privileges to root and execute commands and read files as a system administrator.
A remote attacker without credentials can set passwords on certain disabled accounts.

Note that if this plugin is successful, Nessus has set the password on the 'nobody' account to 'nessus', and you will need to reset this password/re-disable this account to clean up.


Apply Apple Security Update 2017-001.

See Also

Plugin Details

Severity: High

ID: 105003

File Name: macos_10_13_auth_bypass_remote_check.nasl

Version: $Revision: 1.2 $

Type: remote

Family: Misc.

Published: 2017/12/04

Modified: 2017/12/05

Dependencies: 10267

Risk Information

Risk Factor: High


Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x, cpe:/o:apple:macos

Excluded KB Items: global_settings/supplied_logins_only

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2017/11/29

Vulnerability Publication Date: 2017/11/28

Reference Information

CVE: CVE-2017-13872

BID: 101981

OSVDB: 169984