peter bassill · operator
$ cve CVE-1999-1020 JSON

CVE-1999-1020 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.13% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published1998-09-18
Last modified2026-06-16

Affected (1)

VendorProduct
novellnetware

Public exploits

SourceTitleDate
exploit-dbNovell Netware 4.1/4.11 - SP5B NDS Default Rights1999-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD