CVE-1999-1573: Critical severity HPE HP-UX vulnerability
Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HPE HP-UX r-cmndsfrom your environment.Uninstall or remove the r-cmnds package (remshd, rexecd, rlogind, rlogin, remsh, rcp, rexec, rdist) from HP-UX 10.00 through 11.00 systems if the functionality is not required.
- Configuration
Disable the listed r-cmnds services on affected HP-UX systems (HP-UX 10.00 through 11.00) if they are not required.
HPE HP-UX r-cmnds (remshd, rexecd, rlogind, rlogin, remsh, rcp, rexec, rdist) service_enabled = disable - Compensating control
Restrict network access to hosts offering r-cmnds services to trusted management networks or IP addresses using firewall rules, VPNs, or network segmentation to prevent remote attackers from reaching these services.
- Operational
Investigate systems for signs of compromise (privilege escalation or unauthorized file access). If compromise is suspected, isolate affected hosts, rotate credentials/keys, and restore systems from known-good backups as part of incident response.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1573?
CVE-1999-1573 is classified as a high-severity vulnerability due to its potential to allow privilege escalation and unauthorized file access.
How do I fix CVE-1999-1573?
To fix CVE-1999-1573, update your HP-UX systems to the latest patches or versions that address these vulnerabilities.
What specific services are affected by CVE-1999-1573?
CVE-1999-1573 affects remshd, rexecd, rlogind, rlogin, remsh, rcp, rexec, and rdist services on HP-UX.
Which versions of HP-UX are impacted by CVE-1999-1573?
CVE-1999-1573 impacts HP-UX versions 10.00 through 11.00.
Can attackers exploit CVE-1999-1573 remotely?
Yes, attackers can exploit CVE-1999-1573 remotely to gain unauthorized privileges or access files.