CVE-1999-0517 describes a critical vulnerability where Simple Network Management Protocol (SNMP) community strings are set to default, null, or missing values, impacting HP-UX and SunOS systems. This allows unauthenticated attackers to gain unauthorized access to device information and potentially modify configurations, leading to full compromise (C, I, A: P) with low attack complexity (AC:L) over the network (AV:N). While not listed on KEV, the vulnerability has a high EPSS score of 0.90468, indicating a significant likelihood of exploitation, and Metasploit modules exist for enumeration and community string scanning, despite a lack of public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10:*:*:*:*:*:*:* | ||
11.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.