CVE-2017-2488: Apple Remote Desktop

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.

Affected products

  • Apple Remote Desktop: before 3.9 (fixed in 3.9)

Published 2021-12-23. Last modified 2026-06-17.