First published: Fri Dec 31 1999(Updated: )
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Resource Manager | =1.0 | |
Cisco Resource Manager | =1.1 | |
=1.0 | ||
=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1042 is considered a high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-1999-1042, restrict access to the log and temporary files to prevent unauthorized users from reading them.
CVE-1999-1042 affects Cisco Resource Manager versions 1.0 and 1.1.
CVE-1999-1042 can expose sensitive information such as user IDs, passwords, and SNMP community strings.
Mitigating factors for CVE-1999-1042 include proper user access controls and regularly auditing log file permissions.