First published: Wed Jun 23 1999(Updated: )
SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cabletron Spectrum Enterprise Manager | =5.0 | |
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1019 is considered a high severity vulnerability due to the potential for local users to gain elevated privileges.
To fix CVE-1999-1019, secure the directory permissions for SpectroSERVER to prevent local users from replacing privileged executables.
CVE-1999-1019 affects users of Cabletron Spectrum Enterprise Manager version 5.0.
Exploiting CVE-1999-1019 allows local users to execute malicious code with elevated privileges, potentially leading to a complete system compromise.
While CVE-1999-1019 is an older vulnerability, it remains relevant for organizations still using vulnerable versions of Cabletron Spectrum Enterprise Manager.