CVE-1999-0186: Critical severity Sun Solaris vulnerability
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the SNMP subagent's default community string to a strong, unique, non-default community string in the SNMP configuration; remove any entries that use the vendor/default community.
SNMP subagent (Oracle Solaris) community string = non-default strong community string - Configuration
Disable the SNMP subagent if SNMP functionality is not required on the system.
SNMP subagent (Oracle Solaris) enabled = disabled - Compensating control
Restrict network access to the SNMP service (UDP/161) to trusted management hosts/networks using firewalls, ACLs or network segmentation to prevent remote attackers from reaching the SNMP subagent.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0186?
CVE-1999-0186 is considered critical due to the potential for remote attackers to execute arbitrary commands as root.
How do I fix CVE-1999-0186?
To fix CVE-1999-0186, change the default SNMP community string from its default value to a more secure option.
What systems are affected by CVE-1999-0186?
CVE-1999-0186 specifically affects Solaris version 2.6.
What potential impact does CVE-1999-0186 have?
CVE-1999-0186 allows attackers to modify system parameters or execute arbitrary commands, compromising system integrity.
Is CVE-1999-0186 still a risk today?
While CVE-1999-0186 is an older vulnerability, systems running Solaris 2.6 remain at risk if not patched or secured.