CVE-2000-0159: High severity HPE HP-UX vulnerability
HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Avoid using HP Ignite-UX to create images of trusted/production systems. Restrict image creation to non-privileged or test systems, and limit access to any images created with Ignite-UX until verified.
- Operational
For any image created with HP Ignite-UX, inspect the image's /etc/passwd. If password fields are blank or missing, restore correct entries and immediately reset/rotate the affected accounts' passwords.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0159?
CVE-2000-0159 is considered high severity due to the potential for privilege escalation.
How do I fix CVE-2000-0159?
To fix CVE-2000-0159, ensure that HP Ignite-UX is updated to a version that properly handles the /etc/passwd file.
What systems are affected by CVE-2000-0159?
CVE-2000-0159 affects HP-UX version 11.00.
What are the risks associated with CVE-2000-0159?
The risks of CVE-2000-0159 include unauthorized access to systems due to blank password fields.
Is there a workaround for CVE-2000-0159?
A potential workaround for CVE-2000-0159 is to manually restore the /etc/passwd file after creating an image with HP Ignite-UX.