TELNET: Microsoft Telnet Client Information Disclosure

This signature detects information disclosure attempts. Attackers can remotely read session variables for users who have an open connection to a malicious telnet server.

Extended Description

The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

Affected Products

Microsoft windows_2003_server

Short Name
TELNET:SVRRESP:MS-CLIENT-INFO
Severity
Minor
Recommended
False
Recommended Action
None
Category
TELNET
Keywords
CVE-2005-1205 Client Disclosure Information Microsoft Telnet bid:13940
Release Date
06/14/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?