CVE-1999-0502: High severity Sun SunOS vulnerability

Published Mar 1, 1998
·
Updated

A Unix account has a default, null, blank, or missing password.

Affected Software

7 affected components
Sun SunOS=5.7
HP HP-UX=11
Sun SunOS=5.8
Sun SunOS=5.5.1
HP HP-UX=10.20
redhat Linux=6.0
Sun Solaris=2.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove unix/account from your environment.

    If the account is not required for operation, remove the account from the system (for example using userdel or the platform-equivalent account removal method).

  2. Configuration

    Set a non-empty, strong password for the affected account using the system's password management utilities (e.g., passwd or equivalent) so the account does not have a default, null, blank, or missing password.

    Unix account (HPE HP-UX, Oracle Solaris/ZFS, Red Hat Linux, SunOS) password = non-empty strong password
  3. Configuration

    Temporarily lock or disable the account and/or set its login shell to a non-interactive shell (for example nologin/false or the platform equivalent) until the account is reviewed and a proper password is set.

    Unix account (HPE HP-UX, Oracle Solaris/ZFS, Red Hat Linux, SunOS) account_enabled/login_shell = disabled or non-interactive shell
  4. Compensating control

    Until accounts are corrected, restrict access to the affected hosts and services (firewall rules, ACLs, service allowlists) to trusted IPs and administrators to reduce risk of unauthorized access.

  5. Operational

    Perform a system-wide audit to identify any accounts with default/null/blank/missing passwords, rotate credentials for impacted accounts, and review account privileges (including sudoers) to ensure least privilege.

Event History

Mar 1, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0502?

CVE-1999-0502 is considered a critical vulnerability due to the potential for unauthorized access on systems with default or blank passwords.

2

How do I fix CVE-1999-0502?

To fix CVE-1999-0502, ensure that all Unix accounts have strong, non-blank passwords set and implement policies for regular password updates.

3

What systems are affected by CVE-1999-0502?

CVE-1999-0502 affects various versions of HP-UX, Red Hat Linux, and SunOS as listed in the vulnerability details.

4

Can CVE-1999-0502 be exploited remotely?

Yes, CVE-1999-0502 can be exploited remotely if attackers have access to the login prompt of the affected systems.

5

What are the potential consequences of CVE-1999-0502 exploitation?

Exploitation of CVE-1999-0502 can lead to complete system compromise, allowing attackers to execute arbitrary commands and access sensitive data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203