CVE-1999-0476: Weak Encryption
A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SCO TermVisionfrom your environment.Uninstall or remove the SCO TermVision component if it is not required to eliminate storage of weakly-encrypted passwords.
- Compensating control
Restrict local access to systems running SCO TermVision to trusted administrators only (apply least-privilege local accounts, tighten console/physical access, and use host-based access controls) to reduce risk from local users who could decrypt stored passwords.
- Operational
Assume stored TermVision passwords may be compromised and rotate/change all credentials that were stored or used by SCO TermVision after removing or isolating the component.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0476?
CVE-1999-0476 is considered critical due to the use of a weak encryption algorithm that allows password decryption.
How do I fix CVE-1999-0476?
To mitigate CVE-1999-0476, you should upgrade to a software version that uses strong encryption for passwords.
Who is affected by CVE-1999-0476?
CVE-1999-0476 affects users of SCO TermVision on SCO OpenServer systems.
What kind of vulnerability is CVE-1999-0476?
CVE-1999-0476 is a cryptographic vulnerability due to the weak encryption used for storing passwords.
Can local users exploit CVE-1999-0476?
Yes, local users can exploit CVE-1999-0476 to easily decrypt passwords stored using the weak encryption.