CVE-1999-1100
Estado: ModificadaAlta (7.5)—
Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.35%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://ciac.llnl.gov/ciac/bulletins/i-056.shtml
- http://www.cisco.com/warp/public/770/pixkey-pub.shtml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/1579
- http://ciac.llnl.gov/ciac/bulletins/i-056.shtml
- http://www.cisco.com/warp/public/770/pixkey-pub.shtml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/1579
JSON original (NVD)
Mostrar
{
"id": "CVE-1999-1100",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "1999-12-31T05:00:00.000",
"references": [
{
"url": "http://ciac.llnl.gov/ciac/bulletins/i-056.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://www.cisco.com/warp/public/770/pixkey-pub.shtml",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/1579",
"source": "cve@mitre.org"
},
{
"url": "http://ciac.llnl.gov/ciac/bulletins/i-056.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.cisco.com/warp/public/770/pixkey-pub.shtml",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/1579",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack."
}
],
"lastModified": "2026-06-16T21:49:43.327",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:pix_private_link:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E124299F-F51D-4603-B0E8-10E542360372",
"versionEndIncluding": "4.1\\(6\\)"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}