Hp UxOperating system · Hp

CVE-1999-1573

HIGH · 10.0 CVSS v2.0 Published 1999-12-28
Patch available
A vendor patch is available. No clean upgrade release — apply the published patch.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis

A detailed technical summary for this CVE is being prepared.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Hp UxOperating system
Affected:= 10.00= 10.01= 10.10= 10.20= 10.30= 11.00

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:L/Au:N/C:C/I:C/A:C

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Patch available Apply the vendor patch
Vendor patch www.auscert.org.au →
Recommended fix Moderate confidence

Upgrade to a supported HP-UX version (11.11 or later) or migrate to a modern operating system, as HP-UX 10.x reached end-of-support years ago

  1. 1. Identify all systems running the affected HP-UX versions (10.00, 10.01, 10.10, 10.20)
  2. 2. Disable the insecure 'r-commands' services (remshd, rexecd, rlogind, rlogin, remsh, rcp, rexec, rdist) by removing or commenting out their entries in /etc/inetd.conf
  3. 3. Run 'inetd -c' or restart the inetd service to apply changes
  4. 4. Verify that the services are no longer listening on ports 512 (rexec), 513 (rlogin), 514 (rsh), and 515 (rdist) using 'netstat -an | grep -E '(512|513|514|515)'
  5. 5. Remove or rename the vulnerable binaries (/usr/sbin/remshd, /usr/bin/rexecd, /usr/sbin/rlogind, /usr/bin/rlogin, /usr/bin/remsh, /usr/bin/rcp, /usr/bin/rexec, /usr/bin/rdist) as an additional safeguard
  6. 6. Replace all r-command usage with SSH-based alternatives (ssh, scp, sftp) for any legitimate remote administration needs
  7. 7. Implement network-level access controls to block these ports at firewall/ACL level if the services cannot be disabled immediately
Caveat Disabling r-commands will break any automated scripts or workflows that rely on rsh/rcp/rlogin/rexec; these must be migrated to SSH-based equivalents

Generated from the published advisory — verify against the referenced sources before acting.

We can apply and verify the patch for your build — typical engagement from $1,950. Get the patch applied

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-1999-1573 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-1999-1573 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data