CVE-1999-0167Disclosure(sun / sunos)

LOWCVSS 4.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sun sunos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sunos

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
sunos

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-28: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 101-28
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-1999-0167 : SUNOS NFS FILE HANDLE PREDICTION ALERT 🚨 @Oracle  A legacy NFS file handle prediction vulnerability has been identified in SunOS/Solaris systems — allowing unauthenticated attackers to gain full read/write access to exported filesystems. Risk Severity: Critical for legacy systems (pre-2000); negligible for modern environments Impact: • Full read/write/delete/create permissions on NFS exports • Exposure of sensitive system files (passwords, configs) • Remote system compromise without credentials • Potential backdoor installation and persistent access Root Cause: CWE-334 (Predictable Random Values) SunOS NFS file handles were generated using weak, predictable algorithms based on inode numbers, generation counts, and filesystem IDs. Attackers could enumerate handles and bypass mount authentication entirely. Attackers can: • Query mountd RPC service (port 111) for exported filesystems • Predict valid NFS handles for directories and files • Access NFS exports directly via nfsd (port 2049) • Automate full filesystem compromise without authentication Are You Affected? Vulnerable: • SunOS 4.1.x (all revisions) • Solaris 2.0 – 2.6 (unpatched) Fixed in: Solaris 2.6 patch 105786 and Solaris 7+ Note: Modern systems have cryptographically secure NFS handles; exploitation risk is effectively zero. Immediate Action Required: Decommission: Retire all legacy SunOS/Solaris <7 systems immediately Network Isolation: Segregate remaining systems, block NFS-related ports (2049, 111 TCP/UDP) Disable NFS: Use svcadm disable nfs/server or edit /etc/inetd.conf on older versions Audit & Monitor: Inspect NFS traffic, mount requests, and unusual file access patterns Incident Response: Treat any exposed legacy system as potentially compromised; acquire forensic images and rotate credentials Legacy NFS systems remain a critical security liability. Immediate migration to modern OS platforms is mandatory. 🛡️ #oracle #security #ostorlabCVE

    Post summary

    The post discloses a long‑dated SunOS/Solaris NFS file‑handle prediction vulnerability, detailing its technical aspects, impact, and providing patch and mitigation guidance.

    0000066
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSsunsunos4.1.1--

Explore more