CVE-1999-1213: Medium severity HPE HP-UX vulnerability
Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HPE HP-UX telnetfrom your environment.Uninstall or remove the telnet server/component from HP-UX 10.30 systems if it is not required.
- Configuration
Disable the telnet service on affected HP-UX 10.30 systems (stop the telnet server and remove/disable any inetd/xinetd entries that start telnet).
HPE HP-UX telnet service telnet_enabled = false - Compensating control
Restrict or block network access to TCP port 23 (telnet) to trusted IPs only using firewalls, ACLs, or network segmentation until telnet is disabled or removed.
- Operational
Monitor HPE vendor advisories for a supplied fix for the telnet vulnerability and apply the vendor-supplied update or patch to affected HP-UX 10.30 systems when it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1213?
CVE-1999-1213 is classified as a denial of service vulnerability.
How do I fix CVE-1999-1213?
To fix CVE-1999-1213, update your HP-UX system to a version that addresses this vulnerability.
Who is affected by CVE-1999-1213?
CVE-1999-1213 affects systems running HP-UX 10.30 that utilize the telnet service.
What are the consequences of CVE-1999-1213?
Exploitation of CVE-1999-1213 can lead to a denial of service, disrupting normal operation of the telnet service.
Is CVE-1999-1213 still a risk today?
CVE-1999-1213 presents a risk to legacy systems still using HP-UX 10.30, which may not receive regular updates.