CVE-1999-1126
Cisco Resource Manager < 1.1 - Unauthenticated Sensitive Information Exposure via Insecure File Permissions
Title source: llmDescription
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".
References (3)
Core 3
Core References
Patch, Vendor Advisory third-party-advisory
government-resource
x_refsource_ciac
http://ciac.llnl.gov/ciac/bulletins/i-086.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1575
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/770/crmtmp-pub.shtml
Scores
EPSS
0.0036
EPSS Percentile
28.4%
Details
Status
published
Products (1)
cisco/resource_manager
< 1.1
Published
Dec 31, 1999
Tracked Since
Feb 18, 2026