CVE-1999-1047: High severity BSDI Gauntlet vulnerability
When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure firewall logging is enabled and that logs are being recorded and forwarded to a secure log server; verify that access attempts and firewall decisions are being logged.
Network Associates Gauntlet Firewall logging = enabled - Compensating control
Restrict network access to the Gauntlet firewall (management interfaces and affected services) to trusted IP addresses using upstream ACLs or perimeter controls until patches have been correctly applied and verified.
- Operational
Reinstall the BSDI patches for Gauntlet 5.0 in the correct order as specified by the vendor; verify after reinstallation that firewall access controls behave correctly and that logging is occurring.
- Operational
Audit existing logs and network traffic for signs of access-restriction bypass and unlogged activity; investigate any suspicious findings and remediate impacted systems.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1047?
CVE-1999-1047 is considered a critical vulnerability due to the potential for unauthorized remote access.
How do I fix CVE-1999-1047?
To fix CVE-1999-1047, ensure that all patches for Gauntlet 5.0 BSDI are applied in the correct order.
What systems are affected by CVE-1999-1047?
CVE-1999-1047 affects systems running Gauntlet 5.0 on BSDI.
What type of attack does CVE-1999-1047 allow?
CVE-1999-1047 allows remote attackers to bypass firewall access restrictions.
Does CVE-1999-1047 log unauthorized activities?
CVE-1999-1047 does not log unauthorized activities, making detection difficult.