Beck IPC GmbH IPC@CHIP TelnetD Login Account Brute Force Vulnerability
BID:2771
Info
Beck IPC GmbH IPC@CHIP TelnetD Login Account Brute Force Vulnerability
| Bugtraq ID: | 2771 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1339 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by Siberian <[email protected]> on May 24, 2001. |
| Vulnerable: |
Beck IPC GmbH IPC@CHIP Embedded-Webserver |
| Not Vulnerable: | |
Discussion
Beck IPC GmbH IPC@CHIP TelnetD Login Account Brute Force Vulnerability
The IPC@Chip is a single-chip embedded webserver from Beck GmbH.
The device's inbuilt telnetd service may allow a remote user to repeatedly attempt to login to a given account, without logging or responding to repeated failed login attempts. This could permit an attacker to brute-force a known account name, potentially leading to a compromise of the device's accounts and/or allowing a compromise of its function.
The IPC@Chip is a single-chip embedded webserver from Beck GmbH.
The device's inbuilt telnetd service may allow a remote user to repeatedly attempt to login to a given account, without logging or responding to repeated failed login attempts. This could permit an attacker to brute-force a known account name, potentially leading to a compromise of the device's accounts and/or allowing a compromise of its function.
Solution / Fix
Beck IPC GmbH IPC@CHIP TelnetD Login Account Brute Force Vulnerability
Solution:
The vendor reports that this issue has been remedied and that a "test version is available upon request".
Solution:
The vendor reports that this issue has been remedied and that a "test version is available upon request".
References
Beck IPC GmbH IPC@CHIP TelnetD Login Account Brute Force Vulnerability
References:
References: