Junglewise Threat Intelligence

CVE-1999-1213: HP HP-UX denial of service in telnet service

CVE-1999-1213 · Severity: medium · CVSS 5 · Published 1997-10-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the telnet service of HP-UX 10.30 allows remote attackers to disrupt the availability of the system. By exploiting this flaw, an attacker can cause a denial of service, preventing legitimate users from accessing the server remotely. This could impact business operations by disabling remote management and access to critical legacy infrastructure.

Technical details

A denial of service vulnerability exists in the telnet daemon (telnetd) of HP-UX version 10.30. The flaw allows a remote, unauthenticated attacker to send specially crafted requests or sequences to the telnet service, leading to a service crash or hang. This is a network-based attack that requires no user interaction or prior authentication. Successful exploitation results in the loss of availability for the telnet service on the affected host. While specific root cause details (such as a buffer overflow or resource exhaustion) are not detailed in the legacy advisory, the primary impact is limited to service disruption.

Affected products

  • HP HP-UX 10.30

Timeline

  • 1997-10-01: disclosed: Initial publication date

References

Related threats