CVE-2005-1771
Description
Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
Root cause
"An unspecified vulnerability in HP-UX trusted systems that may be exploited via remshd and/or the telnet -t option to allow remote unauthorized access."
Attack vector
An attacker can exploit this vulnerability remotely against HP-UX systems that have been converted to trusted systems. The advisory indicates the attack vector likely involves remshd (the remote shell daemon) and/or the telnet -t option, though the precise mechanism is not disclosed [ref_id=1]. No authentication or special network position is described as a prerequisite; the vulnerability is reachable over the network without prior access.
Affected code
The advisory does not specify exact functions or file paths. It identifies the affected filesets as InternetSrvcs.INETSVCS-RUN and OS-Core.CORE-SHLIBS (or CORE2-SHLIBS) on HP-UX trusted systems B.11.00 through B.11.23, and notes that the vulnerability may involve remshd and/or the telnet -t option [ref_id=1].
What the fix does
HP released patch kits for most affected versions: PHCO_29249 and PHNE_17030 for B.11.00, PHCO_33215 for B.11.11, and PHCO_32926 for B.11.23 [ref_id=1]. For B.11.22, no patch is available; the workaround is to disable remshd by commenting out its lines in /etc/inetd.conf and to remove the -t option from the telnetd line, then running "/usr/sbin/inetd -c" or rebooting [ref_id=1]. The advisory does not describe what the patches change internally.
Preconditions
- configThe HP-UX system must have been converted to a trusted system.
- configThe system must be running one of the affected versions: B.11.00, B.11.11, B.11.22, or B.11.23.
- networkThe attacker must have network access to the target system.
Reproduction
No public exploit or PoC is included in the bundle.
Generated on Jun 16, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2News mentions
0No linked articles in our index yet.