CVE-1999-0771: Medium severity Compaq Insight Management Agent vulnerability
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Compaq Management Agentsfrom your environment.Uninstall Compaq Management Agents if the product is not required, or remove its web components until a vendor-supplied fix is available.
- Remove
Remove
Compaq Power Managementfrom your environment.Uninstall Compaq Power Management if it is not required, or remove/disable any bundled web-accessible components until a vendor-supplied fix is available.
- Remove
Remove
Compaq Survey Utilityfrom your environment.Uninstall the Compaq Survey Utility if it is not required, or remove/disable its web components until a vendor-supplied fix is available.
- Configuration
Disable or turn off the web components / web interface of Compaq Management Agents and the Compaq Survey Utility until a vendor fix is available to prevent remote directory-traversal file reads.
Compaq Management Agents (web components) / Compaq Survey Utility (web components) web interface = disabled - Compensating control
Restrict network access to the affected products' web interfaces to trusted management networks or specific IPs via firewall/ACLs, place the hosts behind a management-only VPN, or block external access entirely until a patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0771?
CVE-1999-0771 has been classified with a moderate severity level due to its potential impact on information disclosure.
How do I fix CVE-1999-0771?
To fix CVE-1999-0771, apply patches provided by Compaq for the affected Management Agents and Power Management software.
What types of systems are impacted by CVE-1999-0771?
CVE-1999-0771 affects systems running Compaq Insight Management Agents and Compaq Power Management version 2.0.
What is a dot dot attack in relation to CVE-1999-0771?
A dot dot attack, also known as directory traversal, allows attackers to access arbitrary files on a server by exploiting improper input validation.
Can CVE-1999-0771 be exploited remotely?
Yes, CVE-1999-0771 can be exploited remotely, allowing attackers to read sensitive files without physical access to the affected system.