CVE-1999-1258
published 1991-01-15CVE-1999-1258: rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system…
PriorityP416medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.35%
68.4th percentile
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | <= 4.1.1 | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun SunOS 4.1/4.1.1 rpc.pwdauthd information disclosure (ID 00102 / XFDB-1782)
vuldb·2026-04-16·CVSS 5.0
CVE-1999-1258 [MEDIUM] Sun SunOS 4.1/4.1.1 rpc.pwdauthd information disclosure (ID 00102 / XFDB-1782)
A vulnerability was found in Sun SunOS 4.1/4.1.1 and classified as problematic. This affects an unknown function of the component rpc.pwdauthd. The manipulation results in information disclosure.
This vulnerability is identified as CVE-1999-1258. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-qcjm-8xhv-v66h: rpc
ghsa_unreviewed·2022-04-30
CVE-1999-1258 [MEDIUM] GHSA-qcjm-8xhv-v66h: rpc
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1991-01-15
Published