CVE-1999-0168
published 1992-06-04CVE-1999-0168: The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing…
PriorityP421high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.74%
75.1th percentile
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun SunOS 4.1.3/4.1.3c Portmapper privileges management (Nessus ID 11358 / XFDB-80)
vuldb·2026-04-16·CVSS 7.5
CVE-1999-0168 [HIGH] Sun SunOS 4.1.3/4.1.3c Portmapper privileges management (Nessus ID 11358 / XFDB-80)
A vulnerability marked as critical has been reported in Sun SunOS 4.1.3/4.1.3c. The impacted element is an unknown function of the component Portmapper. Performing a manipulation results in improper privilege management.
This vulnerability is reported as CVE-1999-0168. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-r3m3-g7jw-9454: The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypa
ghsa_unreviewed·2022-04-30
CVE-1999-0168 [HIGH] GHSA-r3m3-g7jw-9454: The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypa
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1992-06-04
Published