How to find potentially vulnerable GNU inet-utils telnetd servers on your network
ID: 9b5e0021-98ab-5962-9429-d9b78c7d3567
STIX ID: report--9b5e0021-98ab-5962-9429-d9b78c7d3567
Feed Name: runZero Blog
Threat Score
A recently reported authentication-bypass vulnerability in GNU inet-utils telnetd allows a crafted $USER environment variable to bypass authentication and grant remote, unauthenticated access to any user account (including root). Affects inet-utils telnetd versions 1.9.3 and higher; no CVE or patch is available yet, so the guidance is to disable telnet where possible and tighten network access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
