10
CVSSv2

CVE-2001-1291

Published: 12/07/2001 Updated: 09/02/2024
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.

Vulnerable Product Search on Vulmon Subscribe to Product

3com superstack_ii_ps_hub_40_firmware -

Exploits

source: wwwsecurityfocuscom/bid/3034/info A vulnerability exists in certain models of 3Com hubs and potentially other 3Com network products The affected devices fail to properly restrict the allowed number of login attempts to the inbuilt telnet-based administration interface from remote users Attackers can use brute-force cracking tec ...