CVE-2000-0009: High severity Nortel Optivity Net Architect vulnerability

Published Dec 29, 1999
·
Updated

The bnapass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.

Affected Software

1 affected component
Nortel Optivity Net Architect=2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Modify the bna_pass binary or its startup/wrapper so that it invokes the rm program by absolute path (for example /bin/rm) instead of locating it via the PATH environment variable. Alternatively, ensure the process explicitly sets a safe PATH before executing external commands.

    bna_pass (Nortel Optivity Net Architect) invocation of rm / reliance on PATH = invoke rm using an absolute path (e.g. /bin/rm) or avoid using PATH to locate rm
  2. Configuration

    Ensure the PATH seen by bna_pass contains only trusted system directories and does not include directories writable by local/unprivileged users. Achieve this by hardcoding PATH in the service startup, wrapper script, or adjusting system/service unit files.

    environment / PATH used by bna_pass PATH = trusted directories only (e.g. /bin:/usr/bin) and no directories writable by unprivileged users
  3. Compensating control

    Prevent unprivileged users from placing executables in directories contained in PATH (adjust filesystem permissions) and restrict which users can execute or access bna_pass (local account restrictions, file permission hardening) to reduce the ability to exploit PATH-based execution.

  4. Operational

    Search the system PATH for unauthorized or suspicious 'rm' binaries placed by local users, remove any untrusted copies, and audit the system for signs of compromise resulting from this issue; remediate any detected malicious activity.

Event History

Dec 29, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0009?

CVE-2000-0009 has a high severity level due to its potential for local users to execute arbitrary commands.

2

How do I fix CVE-2000-0009?

To fix CVE-2000-0009, ensure that the PATH variable is not used to locate the 'rm' program by modifying the bna_pass program accordingly.

3

What impact does CVE-2000-0009 have on system security?

CVE-2000-0009 can lead to unauthorized command execution, compromising the integrity and confidentiality of the system.

4

Which software versions are affected by CVE-2000-0009?

CVE-2000-0009 specifically affects version 2.0 of Nortel Optivity Net Architect.

5

Who can exploit CVE-2000-0009?

Local users with access to the Optivity Net Architect application can exploit CVE-2000-0009.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203