DETECTION OVERVIEW
Risk Factors
While the Telnet protocol is an older and vulnerable protocol, it is often enabled by default. Data is sent over the Telnet protocol as plaintext, which increases the risk of exposing passwords to attackers and leading to further exploits of higher-value assets.
The system might change the risk score for this detection.
Kill Chain
Risk Score
—
N/A
Disable Telnet unless required
Configure a firewall to block untrusted IP addresses from accessing devices that have Telnet enabled
Implement strict access controls to devices that have Telnet enabled