Junglewise Threat Intelligence

CVE-1999-1257: Xyplex Terminal Server authentication bypass via special characters

CVE-1999-1257 · Severity: high · CVSS 7.5 · Published 1997-11-26

Executive brief

A vulnerability in Xyplex terminal servers allows unauthorized individuals to bypass the password prompt and gain access to the device. By simply entering a specific character like a question mark or a control sequence at the login screen, an attacker can take control of the system. This could lead to unauthorized access to connected network equipment, data interception, or disruption of network services.

Technical details

The Xyplex terminal server (specifically version 6.0.1S1) contains an authentication bypass vulnerability. The flaw exists in the login handling routine where specific characters, such as a CTRL-Z or a question mark (?), are not correctly processed as input but instead trigger a logic error that grants access without a valid password. This is a remote, unauthenticated attack vector. Successful exploitation allows an attacker to gain administrative or console access to the terminal server, potentially compromising all downstream serial connections and network configurations. Patch information is not explicitly detailed in the historical record, though vendor advisories were previously issued.

Affected products

  • Xyplex Terminal Server 6.0.1S1

Timeline

  • 1997-11-26: disclosed: Initial public disclosure

References