CVE-2001-1339 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 7.5% (pctl 94)
Patch early
A public exploit exists.
Description
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.49% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-307 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-05-24 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| anybus | ipc\@chip |
| anybus | ipc\@chip firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Beck IPC GmbH IPC@CHIP - TelnetD Login Account Brute Force | 2001-05-24 |
References
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html
- http://www.iss.net/security_center/static/6605.php
- http://www.kb.cert.org/vuls/id/198979
- http://www.securityfocus.com/archive/1/186418
- http://www.securityfocus.com/bid/2771
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html
- http://www.iss.net/security_center/static/6605.php
- http://www.kb.cert.org/vuls/id/198979
- http://www.securityfocus.com/archive/1/186418
- http://www.securityfocus.com/bid/2771
→ the Explorer · watch your stack · NVD