CVE-1999-1558: High severity Digital Digital OpenVMS vulnerability
Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable external authentication on affected Digital OpenVMS systems (e.g., OpenVMS 7.1 and earlier) until a vendor-provided fix is available.
OpenVMS (loginout) external authentication = disabled - Compensating control
Restrict network access to affected OpenVMS systems using firewall rules, ACLs, or network segmentation so only trusted management hosts/networks can reach them while the issue is mitigated.
- Operational
Review authentication and system logs for signs of unauthorized access on affected systems; investigate and, if necessary, disable or rotate any potentially compromised accounts or credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1558?
CVE-1999-1558 is classified as a vulnerability that allows unauthorized access due to weaknesses in external authentication management.
How do I fix CVE-1999-1558?
To address CVE-1999-1558, disable external authentication or upgrade to a version of Digital OpenVMS that does not have this vulnerability.
What systems are affected by CVE-1999-1558?
CVE-1999-1558 affects Digital OpenVMS 7.1 and earlier versions, including the AXP architecture.
Is CVE-1999-1558 still a concern today?
While CVE-1999-1558 is an older vulnerability, systems still running affected versions may remain at risk if not addressed.
What happens if CVE-1999-1558 is exploited?
Exploitation of CVE-1999-1558 can allow unauthorized users to gain access to systems, compromising confidentiality and integrity.