CVE-1999-1028: Medium severity symantec pcanywhere vulnerability
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Symantec pcAnywherefrom your environment.If pcAnywhere is not required, uninstall or remove the software to eliminate exposure on port 5631.
- Configuration
Disable pcAnywhere from listening on TCP port 5631, or change its listening port to a non-default port if remote access is required.
Symantec pcAnywhere listening_port = disable or change from 5631 - Compensating control
Block or restrict access to TCP port 5631 (pcAnywhere) at the network edge (firewall/ACLs) or via network segmentation; if remote access is required, allow only trusted management IPs.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1028?
CVE-1999-1028 is categorized as a denial of service vulnerability that can significantly impact system performance.
How does CVE-1999-1028 affect Symantec pcAnywhere 8.0?
CVE-1999-1028 allows remote attackers to overwhelm the system with large amounts of data sent to port 5631, causing high CPU utilization.
How do I fix CVE-1999-1028?
To mitigate CVE-1999-1028, users should consider upgrading to a more recent version of Symantec pcAnywhere that addresses this vulnerability.
What is the attack vector for CVE-1999-1028?
The attack vector for CVE-1999-1028 is remote, as it can be exploited through network communications targeting port 5631.
Is CVE-1999-1028 a common vulnerability?
CVE-1999-1028 is an older vulnerability, but its impact on systems still makes it relevant for users of outdated software like Symantec pcAnywhere 8.0.