CVE-1999-1126

Cisco Resource Manager < 1.1 - Unauthenticated Sensitive Information Exposure via Insecure File Permissions

Title source: llm
STIX 2.1

Description

Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".

References (3)

Core 3
Core References
Patch, Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://ciac.llnl.gov/ciac/bulletins/i-086.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1575
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/770/crmtmp-pub.shtml

Scores

EPSS 0.0036
EPSS Percentile 28.4%

Details

Status published
Products (1)
cisco/resource_manager < 1.1
Published Dec 31, 1999
Tracked Since Feb 18, 2026