Junglewise Threat Intelligence

CVE-1999-0795: Sun NIS+ authentication bypass in rpc.nisd

CVE-1999-0795 · Severity: high · CVSS 7.5 · Published 1998-03-01

Technologies: Sunos. Vendors: Sun Microsystems, Sun.

Executive brief

The NIS+ rpc.nisd server, a directory service used to manage system information across networks, contains a flaw that allows unauthorized users to access the system. An attacker can remotely view sensitive system details, disable activity logging, or tamper with cached data. This could lead to a loss of confidentiality and allow an attacker to hide their tracks while manipulating network resources.

Technical details

The rpc.nisd daemon in NIS+ fails to properly enforce authentication for specific Remote Procedure Call (RPC) functions. A remote, unauthenticated attacker can exploit this by sending crafted RPC requests to the server. Successful exploitation allows the attacker to retrieve system configuration information, disable the server's logging mechanisms to evade detection, or modify internal caches. This vulnerability is classified as an authentication bypass within the NIS+ directory service component.

Affected products

  • Sun Microsystems NIS+ (rpc.nisd)

Timeline

  • 1998-03-01: disclosed

References

Related threats