← Vulnerability feed

Vulnerability record · CVE-2000-0665 · published 17 July 2000

CVE-2000-0665: GAMSoft TelSrv telnet server denial of service via long username

Gamsoft · Telsrv

GAMSoft TelSrv 1.5 and earlier fails to handle an overly long username, allowing a remote attacker to crash the telnet server. The flaw is a straightforward denial of service with no confidentiality or integrity impact, but it can take the service offline for legitimate users.

5.0 CVSS 2.0 Medium EPSS 51% · top 1.1%
5.0CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is a remotely reachable, unauthenticated denial of service with public exploit references and high EPSS, but it only causes availability loss and is not in KEV.

What it is

GAMSoft TelSrv 1.5 and earlier fails to handle an overly long username, allowing a remote attacker to crash the telnet server. The flaw is a straightforward denial of service with no confidentiality or integrity impact, but it can take the service offline for legitimate users.

Impact

An attacker can cause the TelSrv service to become unavailable, disrupting telnet access for all users of the affected host. No data disclosure or code execution is described.

Attack surface

Reachable over the network via the telnet service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. The attacker only needs to supply a long username during the telnet login exchange.

Exploitation

Public exploit and vendor advisory references exist, and EPSS is high (0.5099, ~98.9th percentile), but the CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Upgrade TelSrv to a version later than 1.5 if the vendor provides one; the referenced advisory is tagged Patch, so apply the vendor fix first.
  • If no patched version is available, restrict telnet access to trusted networks or disable the service where it is not needed.
  • Place the service behind a firewall or access control list that limits who can reach the telnet port.
  • Monitor the vendor and advisory references for an updated release and retire the product if it is no longer maintained.

Detection

  • Monitor TelSrv process crashes or restarts and correlate them with inbound telnet connections.
  • Alert on unusually long username strings in telnet authentication attempts logged by the host or network sensors.
  • Watch for repeated connection attempts to the telnet port from a single source that precede a service outage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0665 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2000-0665), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.