cbcvebase.
CVE-1999-0502
published 1998-03-01

CVE-1999-0502: A Unix account has a default, null, blank, or missing password.

PriorityP274high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
53.62%
98.9th percentile
A Unix account has a default, null, blank, or missing password.

Affected

7 ranges
VendorProductVersion rangeFixed in
hphp-ux
hphp-ux
redhatlinux
sunsolaris
sunsunos
sunsunos
sunsunos

Detection & IOCsextracted from sources · hover to see the quote

otherroot:root
  • Detect successful SSH login using default credential root:root on port 22/tcp
  • Vulnerability is confirmed via successful authentication over SSH (port 22/tcp); scan for accounts with null, blank, or default passwords on Unix systems
  • ·The vulnerability applies broadly to any Unix account with a default, null, blank, or missing password — not limited to root or SSH; any service exposing such accounts is in scope
  • ·Detection via IPv6 scanning may be missed by traditional IPv4-only security tools; IPv6-enabled hosts with weak credentials may not be observed by network IDS or correctly logged by SIEMs

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.