VYPR
Unrated severityNVD Advisory· Published May 31, 2005· Updated Apr 16, 2026

CVE-2005-1771

CVE-2005-1771

Description

Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • HPE/HP-UXllm-fuzzy
    Range: B.11.00 - B.11.23

Patches

Vulnerability mechanics

Root cause

"An unspecified vulnerability in HP-UX trusted systems that may be exploited via remshd and/or the telnet -t option to allow remote unauthorized access."

Attack vector

An attacker can exploit this vulnerability remotely against HP-UX systems that have been converted to trusted systems. The advisory indicates the attack vector likely involves remshd (the remote shell daemon) and/or the telnet -t option, though the precise mechanism is not disclosed [ref_id=1]. No authentication or special network position is described as a prerequisite; the vulnerability is reachable over the network without prior access.

Affected code

The advisory does not specify exact functions or file paths. It identifies the affected filesets as InternetSrvcs.INETSVCS-RUN and OS-Core.CORE-SHLIBS (or CORE2-SHLIBS) on HP-UX trusted systems B.11.00 through B.11.23, and notes that the vulnerability may involve remshd and/or the telnet -t option [ref_id=1].

What the fix does

HP released patch kits for most affected versions: PHCO_29249 and PHNE_17030 for B.11.00, PHCO_33215 for B.11.11, and PHCO_32926 for B.11.23 [ref_id=1]. For B.11.22, no patch is available; the workaround is to disable remshd by commenting out its lines in /etc/inetd.conf and to remove the -t option from the telnetd line, then running "/usr/sbin/inetd -c" or rebooting [ref_id=1]. The advisory does not describe what the patches change internally.

Preconditions

  • configThe HP-UX system must have been converted to a trusted system.
  • configThe system must be running one of the affected versions: B.11.00, B.11.11, B.11.22, or B.11.23.
  • networkThe attacker must have network access to the target system.

Reproduction

No public exploit or PoC is included in the bundle.

Generated on Jun 16, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

2

News mentions

0

No linked articles in our index yet.