CVE-1999-0443: Critical severity BMC PATROL Agent vulnerability
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Patrol management interface (BMC Patrol Perform Agent) to trusted hosts only using firewall rules, VPNs, or network ACLs. Block management ports from general Internet access.
- Operational
Rotate administrator passwords for accounts used with the Patrol management software immediately and after any suspected exposure. Review and revoke any sessions/tokens that may have been replayed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0443?
CVE-1999-0443 is considered a high severity vulnerability due to the potential for remote attackers to gain administrator privileges.
How do I fix CVE-1999-0443?
To fix CVE-1999-0443, users should upgrade to a patched version of the BMC Patrol Agent software that addresses the vulnerability.
What types of attacks are associated with CVE-1999-0443?
CVE-1999-0443 is associated with replay attacks where an attacker can capture and reuse messages to steal the administrator password.
Which software versions are affected by CVE-1999-0443?
CVE-1999-0443 affects BMC Patrol Agent version 3.2.3.
Can CVE-1999-0443 be exploited over the network?
Yes, CVE-1999-0443 can be exploited remotely, allowing attackers to conduct unauthorized actions over the network.