CVE-1999-1032: Critical severity digital ultrix vulnerability
Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digital Ultrix/lattelnetfrom your environment.Uninstall the lattelnet (LAT/Telnet Gateway) component from Ultrix 4.1 and 4.2 systems if it is not required.
- Configuration
Disable the LAT/Telnet Gateway (lattelnet) service on Ultrix 4.1 and 4.2 systems to prevent exploitation.
Digital Ultrix (lattelnet) service_enabled = false - Compensating control
Restrict network access to the LAT/Telnet Gateway by blocking its ports/services at the perimeter and internal firewalls or by applying ACLs so only trusted management hosts can reach it.
- Operational
If systems running lattelnet on Ultrix 4.1 or 4.2 were exposed, assume possible root compromise: perform incident response (investigate, remove backdoors, reinstall from trusted media) and rotate all credentials and keys.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1032?
CVE-1999-1032 is considered a critical vulnerability due to the risk of attackers gaining root privileges.
How do I fix CVE-1999-1032?
To fix CVE-1999-1032, ensure that your system is updated to a non-vulnerable version of Ultrix that does not include this flaw.
What systems are affected by CVE-1999-1032?
CVE-1999-1032 affects Digital Ultrix versions 4.1 and 4.2.
Can CVE-1999-1032 be exploited remotely?
Yes, CVE-1999-1032 can be exploited remotely through the LAT/Telnet Gateway.
What impact does CVE-1999-1032 have on system security?
CVE-1999-1032 poses a significant security risk as it allows unauthorized users to execute commands with root privileges.