CVE-2000-0414: Medium severity HP VVOS vulnerability
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict local interactive access to HP-UX 11.X and 10.X systems: limit which user accounts can log in locally, confine administrative access to trusted administrators, and isolate affected hosts from untrusted users or networks (physical or network-based isolation) until a vendor fix is available.
- Operational
Monitor and audit use of the shutdown command on HP-UX 11.X and 10.X: enable and review system logs for unexpected or suspicious invocations of shutdown, investigate signs of local privilege escalation, and perform incident response if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0414?
CVE-2000-0414 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2000-0414?
To fix CVE-2000-0414, apply the appropriate security patch provided by HP for your HP-UX version.
Who is affected by CVE-2000-0414?
CVE-2000-0414 affects local users of HP-UX versions 10.10, 10.20, 10.24, and 11.00.
What type of attack is possible with CVE-2000-0414?
CVE-2000-0414 allows local users to gain elevated privileges on the affected systems.
When was CVE-2000-0414 reported?
CVE-2000-0414 was reported in May 2000.