LiveActive security incident?Get immediate response
CVE Record

CVE-1999-0375: Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute...

Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-1999-0375 describes a buffer overflow in the webd component of Network Flight Recorder 2.0.2-Research. The public record says a remote attacker could execute commands. This is a legacy issue, but any surviving deployment should be treated seriously because command execution can mean full system compromise.

Executive priority

Prioritize investigation if the organization has legacy intrusion-detection infrastructure or archived NFR deployments. The issue is old, but confirmed exposure would carry high impact because the described outcome is remote command execution.

Technical view

The source bundle identifies a buffer overflow in webd for Network Flight Recorder 2.0.2-Research, with remote command execution impact. No CVSS score, CWE mapping, detailed affected CPEs, patch version, or exploit details are provided in the supplied sources.

Likely exposure

Exposure is likely limited to legacy environments still running NFR 2.0.2-Research or archived systems where webd remains reachable. The provided affected-product metadata is incomplete, so asset validation is required before scoping risk.

Exploitation context

The CVE record supports remote command execution, but the bundle does not cite active exploitation, public exploit availability, or CISA KEV listing. Do not assume exploitation in the wild from these sources alone.

Researcher notes

Evidence is sparse. The key facts are product/component, version string, vulnerability class, and impact. There is no supplied technical advisory, patch reference, exploit maturity data, or affected CPE detail beyond the CVE title and description.

Mitigation direction

  • Search asset inventory for Network Flight Recorder 2.0.2-Research systems.
  • Identify whether the webd component is installed or reachable.
  • Check vendor or archived product guidance for supported fixes or retirement paths.
  • Remove, isolate, or restrict access to any exposed webd service.
  • Prioritize replacement if the product is unsupported.

Validation and detection

  • Confirm installed NFR versions from package records or host documentation.
  • Map any webd listener to host ownership and business purpose.
  • Review perimeter and internal exposure for reachable webd services.
  • Document whether the asset is production, lab, or archival.
  • Track remediation evidence and residual exceptions.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-1999-0375 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.