CVE-2001-0554
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 38%
from disclosure to weapon0 days
Published on NVDMar 9
1st PoCJul 18
VulnCheckJul 18
exploitation probability
38%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21018⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.ascftp://patches.sgi.com/support/free/security/advisories/20010801-01-Pftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txthttp://archives.neohapsis.com/archives/hp/2001-q4/0014.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000413http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtmlhttp://online.securityfocus.com/advisories/3476http://online.securityfocus.com/archive/1/199496http://online.securityfocus.com/archive/1/199541http://online.securityfocus.com/archive/1/203000https://exchange.xforce.ibmcloud.com/vulnerabilities/6875