Beck IPC GmbH IPC@CHIP TelnetD Account Enumeration Vulnerability
BID:2773
Info
Beck IPC GmbH IPC@CHIP TelnetD Account Enumeration Vulnerability
| Bugtraq ID: | 2773 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1338 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by Siberian <[email protected]> on May 24, 2001. |
| Vulnerable: |
Beck IPC GmbH IPC@CHIP Embedded-Webserver |
| Not Vulnerable: | |
Discussion
Beck IPC GmbH IPC@CHIP TelnetD Account Enumeration Vulnerability
The IPC@Chip is a single-chip embedded webserver from Beck GmbH.
The device's inbuilt telnetd service may allow a remote user to confirm names of valid telnet accounts.
When an attacker attempts to login to the telnet service with a given user ID, the attacker receives a prompt for the password only if the supplied account name exists. This confirms for the attacker that the given ID is valid.
In combination with brute-force password techniques, to which this device is reportedly vulnerable, this can permit a remote attacker to compromise arbitrary accounts on the system. Properly exploited, this can lead to a compromise of the device's normal operation.
The IPC@Chip is a single-chip embedded webserver from Beck GmbH.
The device's inbuilt telnetd service may allow a remote user to confirm names of valid telnet accounts.
When an attacker attempts to login to the telnet service with a given user ID, the attacker receives a prompt for the password only if the supplied account name exists. This confirms for the attacker that the given ID is valid.
In combination with brute-force password techniques, to which this device is reportedly vulnerable, this can permit a remote attacker to compromise arbitrary accounts on the system. Properly exploited, this can lead to a compromise of the device's normal operation.
References
Beck IPC GmbH IPC@CHIP TelnetD Account Enumeration Vulnerability
References:
References: