SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-0554

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

HIGH 10.0EPSS 38.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 38.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
38.75% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
mit/kerberos · mit/kerberos 5 · netkit/linux netkit · sgi/irix · freebsd/freebsd · ibm/aix · netbsd/netbsd · openbsd/openbsd · sun/solaris · sun/sunos · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.