The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x_server | 10.6.1 | 10.6.1.x |
| apple / mac_os_x_server | 10.6.2 | 10.6.2.x |
| apple / mac_os_x | 10.6.1 | 10.6.1.x |
| apple / mac_os_x_server | 10.6.0 | 10.6.0.x |
| apple / mac_os_x | 10.6.0 | 10.6.0.x |
| apple / mac_os_x | 10.6.2 | 10.6.2.x |