CVE-1999-0692: Critical severity SGI IRIX vulnerability
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable authentication in arrayd's configuration so remote connections require valid credentials and unauthenticated remote root access is prevented.
Array Services daemon (arrayd) authentication = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0692?
CVE-1999-0692 has a high severity due to its potential for remote exploitation and unauthorized root access.
How do I fix CVE-1999-0692?
To fix CVE-1999-0692, enable authentication for the Array Services daemon or disable it entirely if not needed.
What software versions are affected by CVE-1999-0692?
CVE-1999-0692 affects several versions of SGI IRIX, including 6.2 through 6.5.4.
Who is impacted by CVE-1999-0692?
Organizations using affected versions of SGI IRIX or Cray UNICOS are at risk from CVE-1999-0692.
What can attackers do with CVE-1999-0692?
Attackers can exploit CVE-1999-0692 to gain root privileges on vulnerable systems.