CVE-1999-1152: High severity Compaq Microcom Microcom 6000 Access Integrator vulnerability
Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the Access Integrator to disconnect a client after a specified number of failed login attempts or enable an account lockout/rate-limiting feature to prevent repeated brute-force attempts. Set an appropriate threshold and lockout duration.
Compaq Microcom Microcom 6000 Access Integrator disconnect_after_failed_logins = enabled (configure threshold) - Compensating control
Restrict remote access to the Access Integrator to trusted IPs/networks (via firewall, VPN or ACLs) and/or place it behind a rate-limiting proxy or WAF to mitigate remote brute-force attacks until an internal disconnect/lockout control is in place.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1152?
CVE-1999-1152 is considered a high severity vulnerability due to its potential for enabling brute force attacks.
How do I fix CVE-1999-1152?
To mitigate CVE-1999-1152, implement account lockout policies after a defined number of failed login attempts.
What is the impact of CVE-1999-1152 on security?
The impact of CVE-1999-1152 allows attackers to exploit weak authentication mechanisms, increasing the risk of unauthorized access.
Which devices are affected by CVE-1999-1152?
CVE-1999-1152 affects the Compaq Microcom 6000 Access Integrator and its associated firmware.
Can CVE-1999-1152 lead to data breaches?
Yes, CVE-1999-1152 can lead to data breaches if attackers successfully gain access through brute force login attempts.