CVE-1999-0921: Medium severity BMC PATROL Agent vulnerability
BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the BMC Patrol Perform Agent's UDP port to trusted hosts/networks using firewall rules or ACLs. Implement network-level UDP flood protections and rate-limiting at the edge or intermediate routers, and isolate agents from untrusted networks to mitigate UDP flood denial-of-service attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0921?
CVE-1999-0921 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0921?
To mitigate CVE-1999-0921, it is recommended to restrict access to the UDP port used by BMC Patrol or implement rate limiting.
What software versions are affected by CVE-1999-0921?
CVE-1999-0921 affects BMC Patrol Agent version 3.2.5.
Can CVE-1999-0921 be exploited remotely?
Yes, CVE-1999-0921 can be exploited remotely by flooding the UDP port.
What is the impact of exploiting CVE-1999-0921?
Exploitation of CVE-1999-0921 can lead to a denial of service condition for the affected BMC Patrol service.