CVE-1999-1020 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.13% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1998-09-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| novell | netware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Novell Netware 4.1/4.11 - SP5B NDS Default Rights | 1999-04-09 |
References
→ the Explorer · watch your stack · NVD