cbcvebase.
CVE-2020-10188
published 2020-03-06

CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
74.51%
99.4th percentile
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos<= 4.20.15
aristaeos
aristaeos4.21.0 – 4.21.10m
aristaeos4.22 – 4.22.4m
aristaeos4.23 – 4.23.3m
debiandebian_linux
debiandebian_linux
debianinetutils< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
debiannetkit-telnet< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
debiannetkit-telnet-ssl< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.2-1ubuntu0.1~esm22:1.9.2-1ubuntu0.1~esm2
gnuinetutils>= 0 < 2:1.9.4-1ubuntu0.1~esm32:1.9.4-1ubuntu0.1~esm3
gnuinetutils>= 0 < 2:1.9.4-3ubuntu0.1+esm22:1.9.4-3ubuntu0.1+esm2
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos

Detection & IOCsextracted from sources · hover to see the quote

pathutility.c
  • Detect exploitation attempts targeting telnetd via short writes or urgent data triggering buffer overflow in netclear/nextitem functions
  • Monitor for unauthenticated remote connections sending specially crafted telnet packets to telnetd; exploitation does not require authentication
  • Check Point IPS signature available for this CVE affecting Cisco IOS XE Telnet service
  • Vulnerability is in telnet-server package (telnetd), not the telnet client; audit hosts for telnet-server installation and enabled telnetd service
  • SELinux in enforcing mode provides partial mitigation by limiting operations executable from telnetd context
  • Telnet-based management service on PAN-OS is disabled by default; alert if it is found enabled
  • ·Vulnerability was publicly disclosed via blog post on February 28, 2020 by APPGATE; patch availability varies by vendor/platform
  • ·PAN-OS: issue is not exploitable if Telnet-based administrative management service is disabled; SSH and HTTPS management interfaces are not affected
  • ·PAN-OS fixed versions: 8.1.20, 9.0.14, 9.1.9, 10.0.6 and all later versions

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_oracle8.3CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.