« Volver al listado

CVE-1999-0612

Estado: ModificadaBaja (0)—

A version of finger is running that exposes valid user information to any entity on the network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-1999-0612",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 0,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 0,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "1997-03-01T05:00:00.000",
  "references": [
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-1999-0612",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-1999-0612",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A version of finger is running that exposes valid user information to any entity on the network."
    }
  ],
  "lastModified": "2026-06-16T21:48:44.177",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:finger_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8572DBD7-169E-4012-A5BA-4E50412526E6"
            },
            {
              "criteria": "cpe:2.3:a:gnu:fingerd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "843643A1-2F59-4F76-8E94-B45C88806345"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_nt:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED27882B-A02A-4D5F-9117-A47976C676E0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.",
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "The FTP Service should be disabled because it could reveal information about a host's users, which could be used as reconnaissance information for attacks."
}