{"id":"CVE-1999-1258","title":"rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.","summary":"rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.","severity":"medium","cvss":5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","published":"1991-01-15","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1258","references":[{"url":"http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/102","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/1782","label":"cve@mitre.org"},{"url":"http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/102","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/1782","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01344,"epssPercentile":0.70146,"ingestedAt":"2026-06-19T03:39:00.678Z","slug":"CVE-1999-1258","body":"## Overview\n\nrpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}