CVE-1999-1074: High severity webmin webmin vulnerability
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Webminto a version that resolves this vulnerability.Fixed in 0.5 - Compensating control
If you cannot immediately upgrade, mitigate brute-force risk by restricting access to the Webmin administrative interface (e.g., firewall/ACLs to trusted IPs), and deploy rate-limiting or a WAF/IPS to block or slow repeated failed login attempts; monitor authentication logs for suspicious activity.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1074?
CVE-1999-1074 has a critical severity level as it allows remote attackers to perform brute force password cracking.
How do I fix CVE-1999-1074?
To fix CVE-1999-1074, upgrade to a version of Webmin that is later than 0.5, which restricts invalid password attempts.
Who is affected by CVE-1999-1074?
CVE-1999-1074 affects all versions of Webmin before 0.5 including versions 0.1 through 0.42.
What impact does CVE-1999-1074 have on users?
CVE-1999-1074 can potentially allow unauthorized users to gain administrative privileges by successfully guessing user passwords.
Is CVE-1999-1074 still a risk today?
While CVE-1999-1074 is an older vulnerability, if outdated versions of Webmin are still in use, it poses a significant security risk.