A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-28751

CVE-2024-28751: Authentication Bypass Vulnerability

CVE-2024-28751 is an authentication bypass vulnerability that allows privileged attackers to enable telnet access with hardcoded credentials. This article covers the technical details, security impact, and mitigation strategies.

Published: May 26, 2026

CVE-2024-28751 Overview

CVE-2024-28751 describes a hardcoded credentials weakness disclosed through VDE Security Advisory VDE-2024-012. A high-privileged remote attacker can enable a telnet service that accepts hardcoded credentials embedded in the affected product. Once telnet is enabled, any actor who knows the embedded credentials can authenticate over the network. The flaw is categorized under [CWE-798] (Use of Hard-coded Credentials) and carries a network attack vector with changed scope, affecting confidentiality, integrity, and availability.

Critical Impact

An authenticated attacker with high privileges can activate a telnet interface that grants access via fixed credentials, exposing the device to full compromise from anyone who knows or recovers those credentials.

Affected Products

  • Product details published through the VDE CERT advisory VDE-2024-012
  • Specific vendor and product identifiers were not populated in the NVD record at time of writing
  • Refer to the VDE Security Advisory VDE-2024-012 for the authoritative list of affected models and firmware versions

Discovery Timeline

  • 2024-07-09 - CVE-2024-28751 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2024-28751

Vulnerability Analysis

The vulnerability allows a remote actor with high privileges to switch on a telnet service that has been shipped with hardcoded credentials. Telnet transmits credentials and session data in cleartext, so any subsequent authentication using the embedded credentials traverses the network without protection. The condition combines two distinct weaknesses: an administrative function that activates a legacy management service, and a backend account whose credentials cannot be changed by operators.

Because the credentials are static across deployments, recovery of the secrets from a single device or from firmware extraction is sufficient to authenticate against every other affected device on which telnet has been enabled. Successful exploitation grants the attacker the privileges associated with the embedded account, which typically exceed those of a standard operator.

Root Cause

The root cause is the inclusion of fixed authentication material inside the device firmware, mapped to [CWE-798]. The affected service trusts credentials that are stored in the image rather than provisioned per device, and there is no mechanism documented for operators to rotate or disable the credentials independently of disabling the service.

Attack Vector

Exploitation requires network reachability to the management interface and an account with high privileges to first enable telnet. After activation, an attacker with knowledge of the embedded credentials authenticates over TCP without requiring user interaction. The changed scope component reflects that compromise of the telnet account can affect resources beyond the originally authorized component.

No public proof-of-concept code is referenced in the advisory, and no verified exploitation in the wild has been reported.

Detection Methods for CVE-2024-28751

Indicators of Compromise

  • Unexpected inbound TCP connections to port 23 on affected devices
  • Configuration changes that enable the telnet service outside approved maintenance windows
  • Authentication events on the device using accounts that are not part of the operator identity store
  • New administrative sessions originating from unfamiliar source IP addresses

Detection Strategies

  • Audit device configuration exports for telnet-enable directives and alert on any deviation from a known-good baseline
  • Inspect network telemetry for cleartext telnet traffic on operational technology and management VLANs
  • Correlate privileged configuration changes with the identity of the operator who performed them to detect account abuse

Monitoring Recommendations

  • Forward device syslog and configuration audit events to a centralized log platform for retention and search
  • Create alerts that fire when telnet is enabled, when a session is established, or when authentication succeeds against the embedded account
  • Continuously scan the management network for listening telnet services and flag any new exposures

How to Mitigate CVE-2024-28751

Immediate Actions Required

  • Apply the firmware update referenced in VDE Security Advisory VDE-2024-012 once available for your hardware revision
  • Verify that telnet is disabled on every affected device and remove any saved configurations that enable it
  • Restrict the management interface to a dedicated administration network protected by firewall rules and jump hosts
  • Review and reduce the number of accounts that hold the high-privilege role required to enable telnet

Patch Information

Refer to VDE Security Advisory VDE-2024-012 for vendor-supplied firmware versions that remediate the hardcoded credentials issue. Validate firmware integrity before deployment and follow the vendor change-control guidance for production devices.

Workarounds

  • Block TCP port 23 at perimeter and segmentation firewalls to prevent reachability of telnet from untrusted networks
  • Use access control lists on the device itself to restrict management protocols to authorized administrative hosts
  • Require administrators to authenticate through an out-of-band management network with multi-factor authentication on the upstream jump host
  • Monitor for and alert on any configuration command that toggles the telnet service state
bash
# Example perimeter rule to block telnet to device management subnet
iptables -A FORWARD -p tcp --dport 23 -d 10.10.20.0/24 -j DROP
iptables -A FORWARD -p tcp --sport 23 -s 10.10.20.0/24 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechTelnet

  • SeverityCRITICAL

  • CVSS Score9.1

  • EPSS Probability1.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-798
  • Technical References
  • VDE Security Advisory VDE-2024-012
  • Related CVEs
  • CVE-2026-22321: CLI Login Buffer Overflow Vulnerability

  • CVE-2026-22542: Telnet Service DOS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English