CVE-1999-0502
published 1998-03-01CVE-1999-0502: A Unix account has a default, null, blank, or missing password.
PriorityP274high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
53.62%
98.9th percentile
A Unix account has a default, null, blank, or missing password.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| redhat | linux | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect successful SSH login using default credential root:root on port 22/tcp ↗
- →Vulnerability is confirmed via successful authentication over SSH (port 22/tcp); scan for accounts with null, blank, or default passwords on Unix systems ↗
- ·The vulnerability applies broadly to any Unix account with a default, null, blank, or missing password — not limited to root or SSH; any service exposing such accounts is in scope ↗
- ·Detection via IPv6 scanning may be missed by traditional IPv4-only security tools; IPv6-enabled hosts with weak credentials may not be observed by network IDS or correctly logged by SIEMs ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxmx-mhq2-c8w6: A Unix account has a default, null, blank, or missing password
ghsa_unreviewed·2022-04-30
CVE-1999-0502 [HIGH] GHSA-wxmx-mhq2-c8w6: A Unix account has a default, null, blank, or missing password
A Unix account has a default, null, blank, or missing password.
VulnCheck
Unix Distributions Account Credentials Vulnerability
vulncheck·1999·CVSS 7.5
CVE-1999-0502 [HIGH] Unix Distributions Account Credentials Vulnerability
Unix Distributions Account Credentials Vulnerability
A Unix account has a default, null, blank, or missing password.
Affected: HP hp-ux
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.pentestpartners.com/security-blog/filling-in-gaps-in-mirai-its-about-dvrs-not-cameras/
No detection rules found.
Exploit-DB
Varnish Cache CLI Interface - Remote Code Execution (Metasploit)
exploitdb·2014-12-19
CVE-2009-2936 Varnish Cache CLI Interface - Remote Code Execution (Metasploit)
Varnish Cache CLI Interface - Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Varnish Cache CLI Interface Bruteforce Utility',
'Description' => 'This module attempts to login to the Varnish Cache (varnishd) CLI instance using a bruteforce
list of passwords. This module will also attempt to read the /etc/shadow root password hash
if a valid password is found. It is possible to execute code as root with a valid password,
however this is not yet implemented in this module.',
'References' =>
[
[ 'OSVDB', '67670' ],
[ 'CVE', '2009-2936' ],
# General
[ 'URL', 'https://www.varnish-cache.org/trac/wiki/CLI' ],
[ 'CVE', '1999-0502']
Exploit-DB
SSH - User Code Execution (Metasploit)
exploitdb·1999-01-01
CVE-1999-0502 SSH - User Code Execution (Metasploit)
SSH - User Code Execution (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
require 'net/ssh'
class MetasploitModule 'SSH User Code Execution',
'Description' => %q{
This module connects to the target system and executes the necessary
commands to run the specified payload via SSH. If a native payload is
specified, an appropriate stager will be used.
},
'Author' => ['Spencer McIntyre', 'Brandon Knight'],
'References' =>
[
[ 'CVE', '1999-0502'] # Weak password
],
'License' => MSF_LICENSE,
'Privileged' => true,
'DefaultOptions' =>
{
'PrependFork' => 'true',
'EXITFUNC' => 'process'
},
'Payload' =>
{
'Space' => 4096,
'BadChars' => "",
'DisableNops' => true
},
'Platform'
Metasploit
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
metasploit
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
This module attempts to authenticate to different D-Link HTTP management services. It has been tested successfully on D-Link DIR-300 Hardware revision B, D-Link DIR-600 Hardware revision B, D-Link DIR-815 Hardware revision A and DIR-645 Hardware revision A devices. It is possible that this module also works with other models.
Metasploit
rsh Authentication Scanner
metasploit
rsh Authentication Scanner
rsh Authentication Scanner
This module will test a shell (rsh) service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below 1024).
Metasploit
Oracle RDBMS Login Utility
metasploit
Oracle RDBMS Login Utility
Oracle RDBMS Login Utility
This module attempts to authenticate against an Oracle RDBMS instance using username and password combinations indicated by the USER_FILE, PASS_FILE, and USERPASS_FILE options. Due to a bug in nmap versions 6.50-7.80 may not work.
Metasploit
rexec Authentication Scanner
metasploit
rexec Authentication Scanner
rexec Authentication Scanner
This module will test an rexec service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below 1024).
Metasploit
DB2 Authentication Brute Force Utility
metasploit
DB2 Authentication Brute Force Utility
DB2 Authentication Brute Force Utility
This module attempts to authenticate against a DB2 instance using username and password combinations indicated by the USER_FILE, PASS_FILE, and USERPASS_FILE options.
Metasploit
Dell iDRAC Default Login
metasploit
Dell iDRAC Default Login
Dell iDRAC Default Login
This module attempts to login to a iDRAC webserver instance using default username and password. Tested against Dell Remote Access Controller 6 - Express version 1.50 and 1.85, Controller 7 - Enterprise 2.63.60.62 Controller 8 - Enterprise 2.83.05 Controller 9 - Enterprise 4.40.00.00
Metasploit
FTP Authentication Scanner
metasploit
FTP Authentication Scanner
FTP Authentication Scanner
This module will test FTP logins on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.
Metasploit
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
metasploit
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
This module attempts to authenticate to different D-Link HTTP management services. It has been tested on D-Link DIR-300 Hardware revision A, D-Link DIR-615 Hardware revision D and D-Link DIR-320 devices. It is possible that this module also works with other models.
Metasploit
WinRM Login Utility
metasploit
WinRM Login Utility
WinRM Login Utility
This module attempts to authenticate to a WinRM service. It currently works only if the remote end allows Negotiate(NTLM) authentication. Kerberos is not currently supported. Please note: in order to use this module without SSL, the 'AllowUnencrypted' winrm option must be set. Otherwise adjust the port and set the SSL options in the module as appropriate.
Metasploit
Tomcat Application Manager Login Utility
metasploit
Tomcat Application Manager Login Utility
Tomcat Application Manager Login Utility
This module simply attempts to login to a Tomcat Application Manager instance using a specific user/pass.
Metasploit
Brocade Enable Login Check Scanner
metasploit
Brocade Enable Login Check Scanner
Brocade Enable Login Check Scanner
This module will test a range of Brocade network devices for a privileged logins and report successes. The device authentication mode must be set as 'aaa authentication enable default local'. Telnet authentication, e.g. 'enable telnet authentication', should not be enabled in the device configuration. This module has been tested against the following devices: ICX6450-24 SWver 07.4.00bT311, FastIron WS 624 SWver 07.2.02fT7e1
Metasploit
NNTP Login Utility
metasploit
NNTP Login Utility
NNTP Login Utility
This module attempts to authenticate to NNTP services which support the AUTHINFO authentication extension. This module supports AUTHINFO USER/PASS authentication, but does not support AUTHINFO GENERIC or AUTHINFO SASL authentication methods.
Metasploit
PostgreSQL Login Utility
metasploit
PostgreSQL Login Utility
PostgreSQL Login Utility
This module attempts to authenticate against a PostgreSQL instance using username and password combinations indicated by the USER_FILE, PASS_FILE, and USERPASS_FILE options. Note that passwords may be either plaintext or MD5 formatted hashes.
Metasploit
D-Link DIR-615H HTTP Login Utility
metasploit
D-Link DIR-615H HTTP Login Utility
D-Link DIR-615H HTTP Login Utility
This module attempts to authenticate to different D-Link HTTP management services. It has been tested successfully on D-Link DIR-615 Hardware revision H devices. It is possible that this module also works with other models.
Metasploit
Wordpress XML-RPC Username/Password Login Scanner
metasploit
Wordpress XML-RPC Username/Password Login Scanner
Wordpress XML-RPC Username/Password Login Scanner
This module attempts to authenticate against a Wordpress-site (via XMLRPC) using username and password combinations indicated by the USER_FILE, PASS_FILE, and USERPASS_FILE options.
Metasploit
MySQL Login Utility
metasploit
MySQL Login Utility
MySQL Login Utility
This module simply queries the MySQL instance for a specific user/pass (default is root with blank).
Metasploit
VMware Authentication Daemon Login Scanner
metasploit
VMware Authentication Daemon Login Scanner
VMware Authentication Daemon Login Scanner
This module will test vmauthd logins on a range of machines and report successful logins.
Metasploit
rlogin Authentication Scanner
metasploit
rlogin Authentication Scanner
rlogin Authentication Scanner
This module will test an rlogin service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below 1024).
Metasploit
HTTP Login Utility
metasploit
HTTP Login Utility
HTTP Login Utility
This module attempts to authenticate to an HTTP service.
Metasploit
SSH User Code Execution
metasploit
SSH User Code Execution
SSH User Code Execution
This module connects to the target system and executes the necessary commands to run the specified payload via SSH. If a native payload is specified, an appropriate stager will be used.
Metasploit
SSH Login Check Scanner
metasploit
SSH Login Check Scanner
SSH Login Check Scanner
This module will test ssh logins on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.
Metasploit
Joomla Bruteforce Login Utility
metasploit
Joomla Bruteforce Login Utility
Joomla Bruteforce Login Utility
This module attempts to authenticate to Joomla 2.5. or 3.0 through bruteforce attacks
Metasploit
PcAnywhere Login Scanner
metasploit
PcAnywhere Login Scanner
PcAnywhere Login Scanner
This module will test pcAnywhere logins on a range of machines and report successful logins.
Metasploit
Telnet Login Check Scanner
metasploit
Telnet Login Check Scanner
Telnet Login Check Scanner
This module will test a telnet login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.
Tenable
Nessus 3.2 BETA - IPv6 Scanning
blogs_tenable·2007-04-16
Nessus 3.2 BETA - IPv6 Scanning
Blog /
Subscribe
# Nessus 3.2 BETA - IPv6 Scanning
Ron Gula
April 16, 2007
7 Min Read
Nessus 3.2 will support scanning of IPv6 addresses. The current BETA (released as Nessus 3.1.3) can be used to perform scans of IPv6 addresses. This blog entry shows how to use the current Nessus 3.2 BETA to perform such a scan from the UNIX command line.
Why Scan for IPv6 Addresses?
More and more operating systems are shipping with IPv6 enabled by default. Both Vista and OS X ship with IPv6 stacks. The presence of IPv6 on your network may dramatically alter how computers communicate with each other and connect to the Internet. Communication that occurs over IPv6 may not be blocked by local or network firewalls, observed by network IDS or even correctly logged by your SIM.
For compliance and corpo
Tenable
Nessus 3.2 BETA - IPv6 Scanning
blogs_tenable·2007-04-16
Nessus 3.2 BETA - IPv6 Scanning
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
1998-03-01
Published
Exploited in the wild