CVE-1999-0627: Low severity IBM AIX vulnerability
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX rexdfrom your environment.Uninstall or remove the rexd daemon/package from systems where it is not required.
- Configuration
Stop and disable the rexd service on affected systems to prevent use of its weak authentication (ensure it is not started at boot or by inetd/xinetd).
IBM AIX (rexd service) enabled = false - Compensating control
If the service cannot be immediately disabled or removed, restrict access to the rexd service from untrusted networks using firewall rules, ACLs, or network segmentation to limit exposure.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0627?
CVE-1999-0627 has a high severity due to the weakness in authentication that allows command execution by an attacker.
How do I fix CVE-1999-0627?
To fix CVE-1999-0627, disable the rexd service or implement strong authentication mechanisms.
Which versions are affected by CVE-1999-0627?
CVE-1999-0627 affects IBM AIX versions 3.1 and 3.2.
What is the impact of CVE-1999-0627?
The impact of CVE-1999-0627 includes potential unauthorized command execution on the affected systems.
How can I determine if CVE-1999-0627 is present on my system?
You can determine if CVE-1999-0627 is present by checking if the rexd service is enabled and assessing the authentication methods used.