peter bassill · operator
$ cve CVE-2007-0882 JSON

CVE-2007-0882 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 98% (pctl 100)

Patch early

A public exploit exists.

Description

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS98.01% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-88
On CISA KEVno
Public exploityes
Published2007-02-12
Last modified2026-06-16

Affected (2)

VendorProduct
oraclesolaris
sunsunos

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD