Junglewise Threat Intelligence

CVE-1999-0612: Generic finger service information disclosure

CVE-1999-0612 · Severity: info · CVSS 0 · Published 1997-03-01

Executive brief

The finger service is an older network protocol used to look up information about users on a specific computer system. When active, it can allow anyone on the network to see details about valid user accounts, such as login names and activity status. This information can be used by malicious actors to perform reconnaissance and plan more targeted attacks against your organization's infrastructure.

Technical details

The finger service (typically running on port 79) is configured in a way that allows unauthenticated remote users to query the system for account information. This is classified as a configuration issue rather than a software flaw, as the protocol is performing its intended function of revealing user details (e.g., usernames, real names, last login times). An attacker can use this information for reconnaissance, such as identifying valid accounts for brute-force attempts or social engineering. Security best practices recommend disabling the finger service to reduce the information available to potential attackers.

Affected products

  • Generic finger service

Timeline

  • 1997-03-01: disclosed: NVD Published Date

References

Related threats