CVE-1999-1151: Medium severity Compaq Microcom Microcom 6000 Access Integrator vulnerability
Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the integrator to enforce a session timeout after prompting for a username or password so unauthenticated connections are terminated after a short period.
Compaq Microcom Microcom 6000 Access Integrator session timeout after credential prompt = enabled (non-zero timeout) - Configuration
Disable remote/unauthenticated management access if remote administration is not required.
Compaq Microcom Microcom 6000 Access Integrator remote management access = disabled if not required - Compensating control
Restrict network access to the integrator's management interface using firewall rules, ACLs, or network segmentation so only trusted hosts can connect, mitigating unauthenticated connection DoS attempts.
- Operational
Contact the vendor for a definitive fix or firmware update and apply any vendor-supplied patches or workarounds when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1151?
CVE-1999-1151 is considered a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-1999-1151?
To fix CVE-1999-1151, it is recommended to apply patches from Compaq or Microcom that address session timeout issues.
What type of attack does CVE-1999-1151 facilitate?
CVE-1999-1151 facilitates denial of service attacks by allowing multiple connections without authentication.
Which software is affected by CVE-1999-1151?
CVE-1999-1151 affects the Compaq Microcom 6000 Access Integrator running the initial version.
Can CVE-1999-1151 be exploited remotely?
Yes, CVE-1999-1151 can be exploited remotely by attackers who attempt to connect to the integrator without providing a username or password.