Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-1999-1126

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-1999-1126
Last Modified 05 Sep 2008 04:18:46
Published 31 Dec 1999 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-1999-1126

Summary

Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".

Vulnerable Systems

Application

  • Cisco Resource Manager 1.1


References

XF - cisco-crm-file-vuln(1575)

CISCO - 19980813 CRM Temporary File Vulnerability

CIAC - I-086


Last Updated: 27 May 2016 10:35:18