First published: Wed Dec 29 1999(Updated: )
The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel Optivity Net Architect | =2.0 | |
=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0009 has a high severity level due to its potential for local users to execute arbitrary commands.
To fix CVE-2000-0009, ensure that the PATH variable is not used to locate the 'rm' program by modifying the bna_pass program accordingly.
CVE-2000-0009 can lead to unauthorized command execution, compromising the integrity and confidentiality of the system.
CVE-2000-0009 specifically affects version 2.0 of Nortel Optivity Net Architect.
Local users with access to the Optivity Net Architect application can exploit CVE-2000-0009.