s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-1999-1231 medium

📛 Threat Title

CVE-1999-1231

Category: vulnerability Published: Source updated: First seen: Last updated: Source: NVD Recent CVEs

Description

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (3)

  • cve@mitre.org NVD Recent CVEs
  • cve@mitre.org NVD Recent CVEs
  • NVD detail: CVE-1999-1231 NVD Recent CVEs

    ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

Remediations (10)

  • web:federalnewsnetwork.com

    CISA this year has already started accelerating the deadlines for agencies to patch software bugs posted to the Known Exploited Vulnerabilities (KEV) catalog.

  • web:github.com

    Patch for Windows 9x to fix CPU issues. Contribute to JHRobotics/patcher9x development by creating an account on GitHub.

  • web:nvd.nist.gov

    Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:scanoncomputer.com

    Explore advanced DoD patch repository and management strategies, tools, and compliance. Stay secure with real-world guides, threat intelligence, and global best practices.

  • web:www.cisa.gov

    Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and ...

  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • web:www.esd.whs.mil

    Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.

  • web:www.threatdown.com

    Fix software vulnerabilities before criminals exploit them with ThreatDown Patch Management. Try it free with a 14-day, no-obligation trial.

  • web:www.virustotal.com

    VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.