CVE-1999-0470: Weak Encryption
A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Novell Remote.NLMfrom your environment.Uninstall Novell Remote.NLM from affected systems if it is not required.
- Configuration
Disable Novell Remote.NLM (prevent the module from loading) to stop use of the weak password encryption algorithm.
Novell Remote.NLM enabled = false - Compensating control
Restrict network access to systems running Novell Remote.NLM/Novell NetWare FTP Server using firewall rules or ACLs; limit access to trusted management networks only.
- Operational
Rotate/change any account passwords that may have been exposed or could be decrypted due to the weak encryption.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0470?
CVE-1999-0470 has been classified as a medium severity vulnerability due to its potential to expose passwords.
How do I fix CVE-1999-0470?
To fix CVE-1999-0470, upgrade to a newer version of Novell NetWare that employs a stronger encryption algorithm.
What systems are affected by CVE-1999-0470?
CVE-1999-0470 affects Novell NetWare version 4.0 specifically.
What is the impact of CVE-1999-0470?
The impact of CVE-1999-0470 is that passwords can be easily decrypted, potentially compromising user accounts.
Is CVE-1999-0470 still a concern today?
While CVE-1999-0470 is an older vulnerability, it remains a concern for systems still running the affected version of Novell NetWare.