CVE-1999-0772: Medium severity Compaq Insight Management Agent vulnerability
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Compaq Management Agentsfrom your environment.Uninstall Compaq Management Agents if the component is not required, or remove it until a vendor-provided remediation is available.
- Remove
Remove
Compaq Power Managementfrom your environment.Uninstall Compaq Power Management if the component is not required, or remove it until a vendor-provided remediation is available.
- Configuration
Stop or disable the Compaq Survey Utility (or reconfigure the Compaq Management Agents) so it no longer listens on TCP port 2301. If the functionality is required, restrict the listener to localhost or an internal management network only.
Compaq Survey Utility (part of Compaq Management Agents) listening on TCP port 2301 = disabled - Compensating control
Block or restrict access to TCP port 2301 at the network perimeter and internal firewalls/ACLs so only trusted management hosts can reach it. If full blocking is not possible, apply filtering to drop malformed/oversized input to that port.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0772?
CVE-1999-0772 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0772?
To mitigate CVE-1999-0772, it is recommended to update or patch the affected Compaq software appropriately.
Which Compaq software is affected by CVE-1999-0772?
CVE-1999-0772 affects Compaq Insight Management Agent and Compaq Power Management version 2.0.
What type of vulnerability is CVE-1999-0772?
CVE-1999-0772 is a denial of service vulnerability specifically targeting port 2301.
Can CVE-1999-0772 be exploited remotely?
Yes, CVE-1999-0772 can be exploited remotely by sending a long string to the affected service.