oss-sec mailing list archives
Re: Telnetd Vulnerability Report
From: "Lyndon Nerenberg (VE7TFX/VE6BBM)" <lyndon () orthanc ca>
Date: Thu, 26 Feb 2026 11:20:45 -0800
Albert Veli writes:
I agree to this, but I can add that telnet remains widely used for login in OT (Operational Technology) environments, including sites running critical infrastructure. While operators often justify this by relying on network isolation, this reasoning breaks down the moment the air gap is bridged.
True, but I suspect that many of those implementations are running in firmware that has been long abandonded. So if you are going to craft a CVE on this, how do you address those legacy systems? Or should a CVE even be written for them, if there is no hope of ever updating the code? We have to accept that there are cases where the problem simply cannot be fixed. At best we can identify them, and warn users of that gear that they have an unrepairable vulnerability that must be addresses independtly. It boils down to "identify and warn." It's important to not get caught up on unsolvable problems. An awful lot of time gets burned up trying to solve things that can't be. --lyndon
Current thread:
- Re: Telnetd Vulnerability Report, (continued)
- Re: Telnetd Vulnerability Report Solar Designer (Feb 24)
- Re: Telnetd Vulnerability Report Lyndon Nerenberg (VE7TFX/VE6BBM) (Feb 24)
- Re: Telnetd Vulnerability Report Vincent Lefevre (Feb 24)
- Message not available
- Re: Telnetd Vulnerability Report kf503bla (Feb 25)
- Re: Telnetd Vulnerability Report Solar Designer (Feb 25)
- Re: Telnetd Vulnerability Report Steffen Nurpmeso (Feb 25)
- Re: Telnetd Vulnerability Report Marco Moock (Feb 25)
- Re: Telnetd Vulnerability Report Steffen Nurpmeso (Feb 25)
- Re: Telnetd Vulnerability Report Lyndon Nerenberg (VE7TFX/VE6BBM) (Feb 25)
- Re: Telnetd Vulnerability Report Albert Veli (Feb 26)
- Re: Telnetd Vulnerability Report Lyndon Nerenberg (VE7TFX/VE6BBM) (Feb 26)
- Re: Telnetd Vulnerability Report Eddie Chapman (Feb 24)
- Re: Telnetd Vulnerability Report Justin Swartz (Feb 24)
- Re: Telnetd Vulnerability Report Eddie Chapman (Feb 24)
- Re: Re: Telnetd Vulnerability Report Marco Moock (Feb 25)
- Re: Re: Telnetd Vulnerability Report Florian Weimer (Feb 26)
- Re: Re: Telnetd Vulnerability Report Demi Marie Obenour (Feb 26)
