CVE-1999-1126: Low severity cisco resource manager vulnerability

Published Dec 31, 1999
·
Updated

Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swimswd.log, (2) swimdebug.log, (3) dbidebug.log, and (4) temporary files whose names begin with "DPR".

Affected Software

1 affected component
Cisco Resource Manager<=1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove temporary files beginning with 'DPR_' from your environment.

    Locate and securely remove unnecessary temporary files whose names begin with 'DPR_'. Ensure the application securely creates and removes such temporary files to avoid leaving sensitive data accessible on disk.

  2. Configuration

    Change filesystem permissions and ownership for swim_swd.log, swim_debug.log, dbi_debug.log and temporary files beginning with 'DPR_' so that unprivileged local users cannot read them (e.g., remove world/group read permissions and set owner to the CRM administrative account or root).

    Cisco Resource Manager (CRM) file_permissions for logs and temporary files = restrict access to administrative user/root (remove world/group read)
  3. Compensating control

    Restrict local access to hosts running Cisco Resource Manager to trusted administrators only (use host-based access controls, ACLs, or isolation) and apply filesystem ACLs or OS-level policies to prevent unprivileged local accounts from reading CRM log and temp files until file permissions are corrected.

  4. Operational

    Assume sensitive configuration data (usernames, passwords, SNMP community strings) may have been exposed. After securing/removing the files, rotate any potentially exposed credentials, secrets, and community strings.

Event History

Dec 31, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1126?

CVE-1999-1126 is considered a high severity vulnerability due to its potential to expose sensitive configuration information.

2

How do I fix CVE-1999-1126?

To fix CVE-1999-1126, ensure that files created by Cisco Resource Manager have appropriate permissions set to restrict access.

3

Who is affected by CVE-1999-1126?

CVE-1999-1126 affects Cisco Resource Manager versions 1.1 and earlier.

4

What information can be exposed by CVE-1999-1126?

CVE-1999-1126 can expose sensitive information such as usernames, passwords, and SNMP community strings.

5

What type of vulnerability is CVE-1999-1126?

CVE-1999-1126 is a local information disclosure vulnerability due to insecure file permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203