CVE-1999-1001: Low severity cisco cache engine vulnerability
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Cisco Cache Engine 550from your environment.If the device is not required, uninstall, decommission, or remove the Cisco Cache Engine 550 from the network to eliminate the vulnerable component.
- Configuration
Disable acceptance of empty/null usernames and passwords (or disable anonymous/guest login). Configure the appliance so all access requires a valid non-empty username and password.
Cisco Cache Engine 550 accept_empty/null username and password = false - Compensating control
Restrict access to the device management and service interfaces to trusted IP ranges or administrative networks using firewall rules, ACLs, or network segmentation to prevent remote exploitation.
- Operational
Review authentication and access logs for signs of access using null or empty credentials and remediate any unauthorized access; change/verify administrative account credentials to ensure they are non-empty and meet policy.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1001?
CVE-1999-1001 has a critical severity rating as it allows remote attackers to gain unauthorized access to the Cisco Cache Engine.
What systems are affected by CVE-1999-1001?
CVE-1999-1001 affects Cisco Cache Engine version 1.0.
How do I fix CVE-1999-1001?
To fix CVE-1999-1001, it is necessary to configure the system with proper username and password credentials.
Can CVE-1999-1001 be exploited remotely?
Yes, CVE-1999-1001 can be exploited remotely by an attacker through a null username and password.
What is the impact of CVE-1999-1001 on security?
CVE-1999-1001 poses a significant risk as it allows attackers to bypass authentication and potentially compromise sensitive data.