Service Report

Global TCP/23 (telnet)

 

Background

Vendors:Conectiva, OpenBSD, Sun, rPath, SGI, APC, Cisco

Vulnerabilities

CVE-2007-0956
Age: 475 days Severity: High CVSS Score: 8.0

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.

CVE-2007-0882
Age: 527 days Severity: High CVSS Score: 10.0

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

CVE-2004-0311
Age: 1338 days Severity: High CVSS Score: 10.0

American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.

CVE-2001-0797
Age: 2415 days Severity: High CVSS Score: 10.0

Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

CVE-2001-0554
Age: 2535 days Severity: High CVSS Score: 10.0

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVE-2001-0170
Age: 2676 days Severity: Low CVSS Score: 2.3

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

CVE-2001-0041
Age: 2714 days Severity: High CVSS Score: 7.8

Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.

CVE-2000-0733
Age: 2833 days Severity: High CVSS Score: 10.0

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

CVE-1999-0501
Age: 3705 days Severity: Medium CVSS Score: 4.9

A Unix account has a guessable password.

CVE-1999-0073
Age: 4667 days Severity: High CVSS Score: 10.0

Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.