CVE-2001-1291

The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
References
Link Resource
http://www.securityfocus.com/archive/1/196957 Broken Link Third Party Advisory VDB Entry Vendor Advisory
http://www.securityfocus.com/bid/3034 Broken Link Exploit Third Party Advisory VDB Entry Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/6855 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:3com:superstack_ii_ps_hub_40_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:3com:superstack_ii_ps_hub_40:-:*:*:*:*:*:*:*

History

09 Feb 2024, 03:14

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/196957 - Vendor Advisory () http://www.securityfocus.com/archive/1/196957 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
References () http://www.securityfocus.com/bid/3034 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/3034 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6855 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6855 - Third Party Advisory, VDB Entry
CWE NVD-CWE-Other CWE-307
First Time 3com superstack Ii Ps Hub 40
3com superstack Ii Ps Hub 40 Firmware
CPE cpe:2.3:h:3com:superstack_ii_ps_hub:40:*:*:*:*:*:*:* cpe:2.3:h:3com:superstack_ii_ps_hub_40:-:*:*:*:*:*:*:*
cpe:2.3:o:3com:superstack_ii_ps_hub_40_firmware:-:*:*:*:*:*:*:*
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 9.8

Information

Published : 2001-07-12 04:00

Updated : 2024-02-09 03:14


NVD link : CVE-2001-1291

Mitre link : CVE-2001-1291

CVE.ORG link : CVE-2001-1291


JSON object : View

Products Affected

3com

  • superstack_ii_ps_hub_40_firmware
  • superstack_ii_ps_hub_40
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts