CVE-2020-10188
published 2020-03-06CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer…
PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
74.51%
99.4th percentile
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | <= 4.20.15 | — |
| arista | eos | — | — |
| arista | eos | 4.21.0 – 4.21.10m | — |
| arista | eos | 4.22 – 4.22.4m | — |
| arista | eos | 4.23 – 4.23.3m | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | inetutils | < inetutils 2:1.9.4-12 (bookworm) | inetutils 2:1.9.4-12 (bookworm) |
| debian | netkit-telnet | < inetutils 2:1.9.4-12 (bookworm) | inetutils 2:1.9.4-12 (bookworm) |
| debian | netkit-telnet-ssl | < inetutils 2:1.9.4-12 (bookworm) | inetutils 2:1.9.4-12 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | inetutils | >= 0 < 2:1.9.4-12 | 2:1.9.4-12 |
| gnu | inetutils | >= 0 < 2:1.9.4-12 | 2:1.9.4-12 |
| gnu | inetutils | >= 0 < 2:1.9.4-12 | 2:1.9.4-12 |
| gnu | inetutils | >= 0 < 2:1.9.4-12 | 2:1.9.4-12 |
| gnu | inetutils | >= 0 < 2:1.9.2-1ubuntu0.1~esm2 | 2:1.9.2-1ubuntu0.1~esm2 |
| gnu | inetutils | >= 0 < 2:1.9.4-1ubuntu0.1~esm3 | 2:1.9.4-1ubuntu0.1~esm3 |
| gnu | inetutils | >= 0 < 2:1.9.4-3ubuntu0.1+esm2 | 2:1.9.4-3ubuntu0.1+esm2 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts targeting telnetd via short writes or urgent data triggering buffer overflow in netclear/nextitem functions ↗
- →Monitor for unauthenticated remote connections sending specially crafted telnet packets to telnetd; exploitation does not require authentication ↗
- →Check Point IPS signature available for this CVE affecting Cisco IOS XE Telnet service ↗
- →Vulnerability is in telnet-server package (telnetd), not the telnet client; audit hosts for telnet-server installation and enabled telnetd service ↗
- →SELinux in enforcing mode provides partial mitigation by limiting operations executable from telnetd context ↗
- →Telnet-based management service on PAN-OS is disabled by default; alert if it is found enabled ↗
- ·Vulnerability was publicly disclosed via blog post on February 28, 2020 by APPGATE; patch availability varies by vendor/platform ↗
- ·PAN-OS: issue is not exploitable if Telnet-based administrative management service is disabled; SSH and HTTPS management interfaces are not affected ↗
- ·PAN-OS fixed versions: 8.1.20, 9.0.14, 9.1.9, 10.0.6 and all later versions ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_oracle8.3CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2025-09-28·CVSS 7.8
CVE-2022-39028 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Several security issues were fixed in Inetutils.
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to esca
Palo Alto
PAN-OS: Impact of Telnet Remote-Code-Execution (RCE) Vulnerability (CVE-2020-10188)
vendor_paloalto·2021-09-08·CVSS 9.8
CVE-2020-10188 [CRITICAL] CWE-120 PAN-OS: Impact of Telnet Remote-Code-Execution (RCE) Vulnerability (CVE-2020-10188)
PAN-OS: Impact of Telnet Remote-Code-Execution (RCE) Vulnerability (CVE-2020-10188)
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
The Telnet-based administrative management service is disabled by default and this issue is not exploitable if this service is disabled.
This issue does not impact SSH or HTTPS management interfaces. This issue does not affect Prisma Access.
Affected products: PAN-OS
Solution: This issue is fixed in PAN-OS 8.1.20, PAN-OS 9.0.14, PAN-OS 9.1.9, PAN-OS 10.0.6, and all later PAN-OS versions.
Workaround: Disabling the Telnet-based administrative management service completely eliminates risks of exploitation of this issue.
This issue requires
Ubuntu
Inetutils vulnerability
vendor_ubuntu·2021-08-20
CVE-2020-10188 Inetutils vulnerability
Title: Inetutils vulnerability
Summary: Inetutils could be made to crash if it received specially crafted
input.
USN-5048-1 fixed a vulnerability in Inetutils for Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. This update provides the corresponding fixes for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Inetutils telnet server allows remote attackers to
execute arbitrary code via short writes or urgent data. An attacker could use
this vulnerability to cause a DoS or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart Inetutils telnetd to make
all the necessary changes.
Ubuntu
Inetutils vulnerability
vendor_ubuntu·2021-08-19
CVE-2020-10188 Inetutils vulnerability
Title: Inetutils vulnerability
Summary: Inetutils could be made to crash if it received specially crafted
input.
It was discovered that Inetutils telnet server allows remote attackers to
execute arbitrary code via short writes or urgent data. An attacker could use
this vulnerability to cause a DoS or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart Inetutils telnetd to make
all the necessary changes.
Oracle
Oracle Oracle Communications Risk Matrix: Mediation server (Telnet) — CVE-2020-10188
vendor_oracle·2021-04-15·CVSS 8.3
CVE-2020-10188 [CRITICAL] Oracle Oracle Communications Risk Matrix: Mediation server (Telnet) — CVE-2020-10188
Oracle Oracle Communications Risk Matrix: Mediation server (Telnet) vulnerability
CVE: CVE-2020-10188
CVSS: 8.3
Protocol: Telnet
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Cisco
Telnet Vulnerability Affecting Cisco Products: June 2020
vendor_cisco·2020-06-24·CVSS 9.8
CVE-2020-10188 [CRITICAL] CWE-120 Telnet Vulnerability Affecting Cisco Products: June 2020
Telnet Vulnerability Affecting Cisco Products: June 2020
On February 28, 2020, APPGATE published a blog post regarding CVE-ID CVE-2020-10188, which is a vulnerability in Telnet servers (telnetd).
For more information about this vulnerability, see the Details section.
Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx
Red Hat
telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
vendor_redhat·2020-02-28·CVSS 9.8
CVE-2020-10188 [CRITICAL] CWE-119 telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
A vulnerability was found where incorrect bounds checks in the telnet server’s (telnetd) handling of short writes and urgent data, could lead to information disclosure and corruption of heap data. An unauthenticated remote attacker could exploit these bugs by sending specially crafted telnet packets to achieve arbitrary code execution in the telnet server.
Statement: This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterpr
Debian
CVE-2020-10188: inetutils - utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to ex...
vendor_debian·2020·CVSS 9.8
CVE-2020-10188 [CRITICAL] CVE-2020-10188: inetutils - utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to ex...
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Scope: local
bookworm: resolved (fixed in 2:1.9.4-12)
bullseye: resolved (fixed in 2:1.9.4-12)
forky: resolved (fixed in 2:1.9.4-12)
sid: resolved (fixed in 2:1.9.4-12)
trixie: resolved (fixed in 2:1.9.4-12)
Cisco
Telnet Vulnerability Affecting Cisco Products: June 2020
vendor_cisco·CVSS 3.1
CVE-2020-10188 Telnet Vulnerability Affecting Cisco Products: June 2020
CVE-2020-10188: Telnet Vulnerability Affecting Cisco Products: June 2020
On February 28, 2020, APPGATE published a blog post regarding CVE-ID CVE-2020-10188, which is a vulnerability in Telnet servers (telnetd). For more information about this vulnerability, see the
CVSS: 3.1
CWE: CWE-120, CWE-120
Bug IDs: CSCvu66723, CSCvu66723
OSV
inetutils vulnerabilities
osv·2025-09-28·CVSS 7.8
CVE-2019-0053 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to escalate their
privileges. (CVE-2023-40303)
GHSA
GHSA-8239-4cq6-qmwc: utility
ghsa_unreviewed·2022-05-24
CVE-2020-10188 [HIGH] CWE-120 GHSA-8239-4cq6-qmwc: utility
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
OSV
CVE-2020-10188: utility
osv·2020-03-06·CVSS 9.8
CVE-2020-10188 [CRITICAL] CVE-2020-10188: utility
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
No detection rules found.
No public exploits indexed.
Checkpoint
29th June – Threat Intelligence Bulletin
blogs_checkpoint·2020-06-29
CVE-2019-10072 29th June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 29th June 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point researchers have discovered an ongoing, evolving campaign from a known hacking group called “DarkCrewFriends.” This campaign targets PHP servers, focusing on creating a botnet infrastructure that can be leveraged for several purposes such as monetization and shutting down critical services.
Check Point IPS p
Bugzilla
CVE-2020-10188 telnet: telnet-server: Arbitrary remote code execution in utility.c via short writes or urgent data [fedora-all]
bugzilla·2020-03-18·CVSS 9.8
CVE-2020-10188 [CRITICAL] CVE-2020-10188 telnet: telnet-server: Arbitrary remote code execution in utility.c via short writes or urgent data [fedora-all]
CVE-2020-10188 telnet: telnet-server: Arbitrary remote code execution in utility.c via short writes or urgent data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2020-10188 telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
bugzilla·2020-03-09·CVSS 9.8
CVE-2020-10188 [CRITICAL] CVE-2020-10188 telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
CVE-2020-10188 telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Discussion:
Statement:
This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterprise Linux host to be vulnerable, it must have telnet-server installed and the telnetd service enabled. Use of telnetd is not recommended, as it is an un-encrypted protocol with cleartext transmission of passwords; alternatives such as openssh are preferred.
---
Created telnet tracking bugs for this issue:
Affects: fedora-all [
https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.htmlhttps://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216https://lists.debian.org/debian-lts-announce/2020/05/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00038.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPxhttps://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48https://www.oracle.com/security-alerts/cpuApr2021.htmlhttp://www.openwall.com/lists/oss-security/2026/01/20/8https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.htmlhttps://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216https://lists.debian.org/debian-lts-announce/2020/05/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00038.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPxhttps://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48https://www.oracle.com/security-alerts/cpuApr2021.html
2020-03-06
Published