CVE-1999-0687: High severity CDE CDE vulnerability
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ToolTalk ttsession daemonfrom your environment.If the daemon is not required, uninstall or disable the ToolTalk ttsession daemon to eliminate exposure to remote command execution via weak RPC authentication.
- Configuration
Configure the ttsession daemon to stop using weak RPC authentication: enable strong RPC authentication mechanisms if available, or disable RPC-based access for the daemon.
ToolTalk ttsession daemon RPC authentication = use strong authentication or disable RPC access - Compensating control
Restrict network access to the ttsession daemon: block or limit incoming RPC connections using host-based firewalls, network ACLs, or perimeter firewalls so only trusted management hosts can reach the service.
- Operational
Assume possible compromise if the service was exposed: review system and audit logs for unauthorized command execution, isolate affected hosts, and perform incident response and remediation as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0687?
CVE-1999-0687 is classified as a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-1999-0687?
To fix CVE-1999-0687, update the affected ToolTalk ttsession daemon to a version that implements stronger RPC authentication.
Which software versions are affected by CVE-1999-0687?
CVE-1999-0687 affects ToolTalk versions 1.0.1, 1.0.2, 1.1, 1.2, 2.0, and various versions of IBM AIX and Sun Solaris.
What is the risk associated with CVE-1999-0687?
The risk associated with CVE-1999-0687 includes unauthorized remote command execution by attackers exploiting weak RPC authentication.
Is CVE-1999-0687 still relevant today?
While CVE-1999-0687 may seem outdated, its implications are still relevant as many systems may still operate on affected software versions.