CVE-2000-0152: Medium severity novell bordermanager vulnerability
Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the telnet service or otherwise stop Novell BorderManager from listening on TCP port 2000 (remove or reconfigure the telnet listener).
Novell BorderManager telnet on TCP port 2000 = disabled - Compensating control
Block or restrict access to TCP port 2000 to the Novell BorderManager using network firewalls, ACLs, or host-based firewalls; allow only trusted management hosts if access is necessary.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0152?
CVE-2000-0152 has been classified as a denial of service vulnerability.
How do I fix CVE-2000-0152?
To mitigate CVE-2000-0152, it is recommended to upgrade Novell BorderManager to a more recent version or implement access control measures to restrict telnet access.
What versions of Novell BorderManager are affected by CVE-2000-0152?
CVE-2000-0152 affects Novell BorderManager versions 3.0 and 3.5.
How does CVE-2000-0152 exploit vulnerability?
CVE-2000-0152 allows remote attackers to crash the service by sending a single enter key through a telnet connection on port 2000.
Can CVE-2000-0152 be exploited remotely?
Yes, CVE-2000-0152 can be exploited remotely by sending specific input to an open telnet session.