Vulnerability Name:

CVE-2001-1291 (CCN-6855)

Assigned:2001-07-12
Published:2001-07-12
Updated:2017-10-10
Summary:The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Thu Jul 12 2001 - 15:46:44 CDT
3Com TelnetD

Source: MITRE
Type: CNA
CVE-2001-1291

Source: CCN
Type: OSVDB ID: 5435
3Com Telnet Server Brute Force Attack

Source: BUGTRAQ
Type: Vendor Advisory
20010712 3Com TelnetD

Source: BID
Type: Exploit, Vendor Advisory
3034

Source: CCN
Type: BID-3034
3Com TelnetD Weak Password Protection Vulnerability

Source: XF
Type: UNKNOWN
3com-telnetd-brute-force(6855)

Source: XF
Type: UNKNOWN
3com-telnetd-brute-force(6855)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:3com:superstack_ii_ps_hub:40:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:3com:superstack_ii_ps_hub:40:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    3com superstack ii ps hub 40
    3com superstack ii ps hub 40