CVE-1999-1160: Critical severity HPE HP-UX vulnerability
Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HPE HP-UX ftpd/kftpdfrom your environment.If ftpd/kftpd is not required, uninstall or remove the ftpd/kftpd binaries from HP-UX 10.x and 9.x systems.
- Configuration
Disable the ftpd/kftpd service on affected HP-UX 10.x and 9.x systems to prevent exploitation.
HPE HP-UX ftpd/kftpd service_enabled = false - Compensating control
Restrict network access to the FTP service (ftpd/kftpd) using firewall rules, host-based ACLs, or network segmentation so only trusted hosts can reach the service; block remote access if not required.
- Operational
Audit system logs and verify root account integrity on HP-UX 10.x and 9.x systems for signs of exploitation; if compromise is suspected, perform incident response (isolate affected systems, restore from known-good backups, and rotate any potentially exposed credentials).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1160?
CVE-1999-1160 has a high severity rating due to its potential to allow unauthorized users to gain root privileges.
How do I fix CVE-1999-1160?
To fix CVE-1999-1160, it is recommended to update to a newer version of HP-UX that does not contain this vulnerability.
Who is affected by CVE-1999-1160?
CVE-1999-1160 affects users of HP-UX 9.x and 10.x operating systems.
Is CVE-1999-1160 a local or remote exploit?
CVE-1999-1160 can be exploited by both local and potentially remote users.
What services are impacted by CVE-1999-1160?
CVE-1999-1160 specifically impacts the ftpd/kftpd services in HP-UX.