CVE-1999-0661

CRITICAL ⚠ Exploit

A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2...

Affects 0 products across 6 vendors.

BCS8.82
CVSS 2.010.0
EPSS54.2%
Percentile99th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A system is running software versions that have been compromised and replaced with a Trojan Horse at distribution points, posing a significant security risk.

BSID: BS-1999-GLOBAL-164541-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-1999-0661?
A system is running software versions that have been compromised and replaced with a Trojan Horse at distribution points, posing a significant security risk.
What is the CVSS score for CVE-1999-0661?
CVE-1999-0661 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 54.2%.
Is CVE-1999-0661 actively exploited?
Public exploit available for CVE-1999-0661. Exploitation risk elevated.
How do I remediate CVE-1999-0661?
Priority: IMMEDIATE.
What systems are affected by CVE-1999-0661?
CVE-1999-0661 affects: Client, Distribution, Ftpd, Linux, Sendmail, Wuftpd.
Vulnerability Details
CVE IDCVE-1999-0661
BSIDBS-1999-GLOBAL-164541-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published1999-01-01
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves malicious actors replacing legitimate software binaries with Trojan Horse versions at distribution points, leading to unauthorized access and potential system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Client —
Distribution —
Ftpd —
Linux —
Sendmail —
Wuftpd —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 10077 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Client
CVE-2025-53624 10.0 The Docusaurus gists plugin adds a page to your Docusaurus instance, displayi... CVE-2025-6512 10.0 On a client with a non-admin user, a script can be integrated into a report. ... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2026-41070 10.0 openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN serve... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th...
View all Client CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →