CVE-1999-1559: Medium severity Alcatel OmniSwitch vulnerability
Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Alcatel OmniSwitch (Xylan OmniSwitch)to a version that resolves this vulnerability.Fixed in 3.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1559?
CVE-1999-1559 is considered a low severity vulnerability as it mainly allows session lockout without compromising data integrity.
How do I fix CVE-1999-1559?
To mitigate CVE-1999-1559, upgrade your Alcatel OmniSwitch firmware to version 3.2.6 or later.
What is the impact of CVE-1999-1559?
The impact of CVE-1999-1559 involves unauthorized access through session bypassing, potentially locking out legitimate users.
Which versions are affected by CVE-1999-1559?
CVE-1999-1559 affects Alcatel OmniSwitch versions prior to 3.2.6.
Can CVE-1999-1559 be exploited remotely?
Yes, CVE-1999-1559 can be exploited remotely as it allows attackers to bypass the login prompt.