Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
10.0CRITICALNVD
EPSS
16.7%
top 5.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 14
Latest updateMay 3

Description

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages8 packages

NVDibm/aix5 versions+4
NVDsgi/irix6.5
NVDsun/sunos9 versions+8
NVDsun/solaris2.6
NVDmit/kerberos1.0

Also affects: Netbsd 1.0, 1.1, 1.2, 1.2.1, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.5, 1.5.1, Freebsd 2.0, 2.0.1, 2.0.5, 2.1, 2.1.0, 2.1.5, 2.1.6, 2.1.6.1, 2.1.7, 2.1.7.1, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.5.1, 4.0, 4.1, 4.1.1, 4.2, 4.3, Debian Linux 2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cxg3-hwc8-9mx4: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of opt2022-05-03
CVEList
CVE-2001-0554: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of opt2002-03-09

💥Exploits & PoCs

1
Exploit-DB
Solaris 2.x/7.0/8 / IRIX 6.5.x / OpenBSD 2.x / NetBSD 1.x / Debian 3 / HP-UX 10 - 'TelnetD' Remote Buffer Overflow2001-07-18

📋Vendor Advisories

3
Cisco
Cisco VPN 3000 Concentrator Multiple Vulnerabilities2002-09-03
Cisco
Cisco CatOS Telnet Buffer Vulnerability2002-01-29
Red Hat
security flaw2001-07-18

💬Community

1
Bugzilla
CVE-2001-0554 security flaw2018-08-16
CVE-2001-0554 — Classic Buffer Overflow in Debian Linux | cvebase