Description
AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://www.venera.com/downloads/Attack_5250_terminal_emulations_from_iSeries_server.pdf
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111160242803070&w=2
Scores
EPSS
0.0170
EPSS Percentile
74.9%
Details
Status
published
Products (4)
bosanova/launcher400
ibm/client_access
mochasoft/tn5250
powerterm/interconnect
Published
May 02, 2005
Tracked Since
Feb 18, 2026