CVE-1999-0170: High severity digital ultrix vulnerability
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digital Ultrix NFS serverfrom your environment.If NFS is not required, disable or uninstall the NFS server on affected Ultrix systems (stop nfsd and related RPC daemons) to eliminate the attack surface.
- Compensating control
Block or restrict network access to NFS-related services on affected hosts using firewall rules or ACLs so only trusted systems can reach NFS (restrict RPC/portmap/mountd/NFS access at the network perimeter).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0170?
CVE-1999-0170 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-1999-0170?
To fix CVE-1999-0170, ensure that proper access control lists are configured and apply any relevant patches provided by your vendor.
Who is affected by CVE-1999-0170?
CVE-1999-0170 affects users of Digital Ultrix and OSF systems where NFS configurations allow unauthorized access.
What kind of attacks can occur with CVE-1999-0170?
Remote attackers can exploit CVE-1999-0170 to mount NFS file systems despite being restricted by access control measures.
Is CVE-1999-0170 still a relevant vulnerability today?
CVE-1999-0170 remains relevant for legacy systems still running Digital Ultrix and OSF that have not been updated.