CVE-1999-1300: Low severity cray unicos vulnerability
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Cray UNICOS/acctonfrom your environment.If accton is not required, uninstall or remove the accton utility from affected systems to eliminate the vulnerable component.
- Compensating control
Restrict local user access to systems running Cray UNICOS: limit which accounts can log in locally, restrict execution of accounting utilities to trusted administrators, and apply tight filesystem permissions on accton and related files.
- Operational
Audit system accounting configuration and sensitive files for unauthorized changes or disclosure, restore impacted configuration/files from known-good backups if tampered with, and review local login/activity logs for possible exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1300?
CVE-1999-1300 is rated as a high severity vulnerability due to its potential to allow local users to read arbitrary files and modify system accounting configurations.
How do I fix CVE-1999-1300?
To fix CVE-1999-1300, apply available patches for Cray UNICOS 6.0 and 6.1 that address the vulnerability.
Who is impacted by CVE-1999-1300?
Local users of Cray UNICOS versions 6.0 and 6.1 are impacted by CVE-1999-1300 as it allows them unauthorized access to sensitive files.
What systems are affected by CVE-1999-1300?
CVE-1999-1300 affects systems running Cray UNICOS versions 6.0 and 6.1.
What type of access is granted by CVE-1999-1300?
CVE-1999-1300 grants local users unauthorized access to read arbitrary files and modify accounting configurations.