VYPR
Unrated severityNVD Advisory· Published Jul 15, 1999· Updated Apr 16, 2026

CVE-1999-1086

CVE-1999-1086

Description

Novell NetWare 5 and earlier allow remote attackers to gain admin privileges by spoofing MAC addresses in IPX fragmented NCP packets when packet signature level is below 3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Novell NetWare 5 and earlier allow remote attackers to gain admin privileges by spoofing MAC addresses in IPX fragmented NCP packets when packet signature level is below 3.

Vulnerability

In Novell NetWare 5 and earlier (including 4.x) running over IPX, fragmented NCP calls (type 0x68) are not cryptographically signed when the packet signature level is set below 3 [1]. This allows an attacker to forge the source MAC address of an administrator and inject arbitrary NCP requests.

Exploitation

An attacker must be on the same IPX network segment to observe or spoof MAC addresses. By capturing the MAC address of an authenticated administrator, the attacker can craft fragmented IPX packets with that spoofed MAC and send NCP calls that the server will accept as coming from the legitimate admin [1]. No additional authentication or user interaction is required.

Impact

Successful exploitation grants the attacker full administrator privileges on the target NetWare server. The attacker can execute any NCP call, including creating or deleting users, modifying files, and compromising the entire NDS tree [1].

Mitigation

Set the packet signature level to 3 on both the server and all clients. This forces all NCP packets, including fragmented ones, to be signed and verified [1]. Alternatively, migrate from IPX to NetWare/IP, which does not rely on MAC address trust. Novell had not released a complete fix at the time of the advisory [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Novell/Netware3 versions
    cpe:2.3:o:novell:netware:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:novell:netware:*:*:*:*:*:*:*:*range: <=5.0
    • cpe:2.3:o:novell:netware:4.1:*:*:*:*:*:*:*
    • cpe:2.3:o:novell:netware:4.11:sp5b:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.