CVE: CVE-2007-0882

Export to Word

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.9135
Percentile: 0.99638

CVSS Scoring

CVSS v2 Score: 10.0

Severity:

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Affected Products

← Back to Home