CVE-1999-0088: Critical severity IBM AIX vulnerability
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX automountd (autofsd)from your environment.Uninstall the automountd (autofsd) service if it is not required on the system.
- Configuration
Disable or stop the automountd service (autofsd) on affected AIX/IRIX systems to prevent remote users from executing commands as root.
IBM AIX automountd (autofsd) autofsd enabled = false - Compensating control
Restrict network access to the automountd (autofsd) service using firewall rules or ACLs; allow access only from trusted management hosts or isolate affected systems from untrusted networks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0088?
CVE-1999-0088 is considered a critical vulnerability due to its ability to allow remote users to execute root commands.
How do I fix CVE-1999-0088?
To fix CVE-1999-0088, it is essential to disable the automountd service or apply relevant security patches provided by IBM.
What systems are affected by CVE-1999-0088?
CVE-1999-0088 affects IRIX and AIX operating systems, specifically versions 4.3 of AIX.
Can CVE-1999-0088 be exploited remotely?
Yes, CVE-1999-0088 can be exploited remotely, allowing attackers to gain unauthorized root access.
What are the consequences of exploiting CVE-1999-0088?
Exploiting CVE-1999-0088 can lead to complete system compromise, data loss, and unauthorized access to sensitive information.