CVE-2001-1291
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.90% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-307
- Affected
- 3com/superstack ii ps hub 40 firmware
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/196957Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3034Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6855Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/196957Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3034Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6855Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.