telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 98.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 100.00 |
VPI 公式 vpi-v1
必要措施
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.