utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Conclusion & alert: CVE-2020-10188 is rated High Risk (79/100): CVSS Critical severity, with high exploitation likelihood (EPSS 74.51%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +66.11% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 8.40% | 74.51% | +66.11% |
| 2 | 2026-05-10 | 9.58% | 8.40% | -1.17% |
| 3 | 2026-04-11 | — | 9.58% | — |
Full EPSS history (41 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-10188 not yet assigned priority: Debian including 3 source packages (inetutils, netkit-telnet, netkit-telnet-ssl), 11 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 11. | https://security-tracker.debian.org/tracker/CVE-2020-10188 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2020-10188 |
suse
|
high | CVE-2020-10188 severity important: SUSE including 8 source package names (krb5-appl-clients-1.0.3-3.3.1, krb5-appl-servers-1.0.3-3.3.1, …), 75 product×package rows across 32 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 5, … (32 product lines)): Fixed 42, Known Not Affected 33. | https://www.suse.com/security/cve/CVE-2020-10188/ |
ubuntu
|
medium | CVE-2020-10188 medium priority: Ubuntu including 3 source packages (inetutils, netkit-telnet, netkit-telnet-ssl), 50 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 18, ignored 12, DNE 7, needs-triage 7, released 6. | https://ubuntu.com/security/CVE-2020-10188 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| netkit_telnet_project | netkit_telnet | <= 0.17 | cpe:2.3:a:netkit_telnet_project:netkit_telnet:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| arista | eos | <= 4.20.15 | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
| arista | eos | >= 4.21.0, <= 4.21.10m | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
| arista | eos | >= 4.22, <= 4.22.4m | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
| arista | eos | >= 4.23, <= 4.23.3m | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
| arista | eos | 4.24.0f | cpe:2.3:o:arista:eos:4.24.0f:*:*:*:*:*:*:* |
| oracle | communications_performance_intelligence_center | 10.4.0.2 | cpe:2.3:a:oracle:communications_performance_intelligence_center:10.4.0.2:*:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:-:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10-s1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10-s2:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r11:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s10:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s11:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s12:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s13:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s14:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s15:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s3:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s4:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s6:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s8:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r13:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r2:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r3:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r4:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r5:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r6:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r7:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r8:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r9:*:*:*:*:*:* |
| juniper | junos | 12.3r12 | cpe:2.3:o:juniper:junos:12.3r12:*:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:-:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d100:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d20:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d25:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d30:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d35:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d40:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d45:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d50:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d51:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d55:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d60:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d65:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d66:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d70:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d75:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d80:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d85:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d90:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d95:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:-:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:d20:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:d30:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:d35:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:d40:*:*:*:*:*:* |
| juniper | junos | 12.3x50 | cpe:2.3:o:juniper:junos:12.3x50:d45:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:-:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:a1:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f1:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f2-s1:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f2-s2:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f2-s3:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f2-s4:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f3:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f4:*:*:*:*:*:* |
| juniper | junos | 15.1 | cpe:2.3:o:juniper:junos:15.1:f5:*:*:*:*:*:* |