Telnet

PCIComplianceHubLast updated

A remote terminal protocol from before encryption was expected, which sends everything, including the login password, across the network in the clear. Any administrative session over it is readable by anyone on the path, which is why it is the standard example of an insecure service.

Applies to. Any in-scope system or device that still has it enabled. Older network equipment and embedded devices are where it survives.
Example. A legacy switch in the payment network accepts Telnet logins. 2.2.4 requires unnecessary services to be disabled; if the device cannot manage without it, 2.2.5 requires a documented business justification and additional security features that reduce the risk, and 2.2.7 still requires administrative access to be encrypted, which Telnet cannot be.
Limits. There is no configuration of Telnet that satisfies 2.2.7; the answer is SSH, a VPN, or a console. Tunnelling it inside an encrypted channel is the one form 'additional security features' can take. A device that offers only Telnet is a device the standard is telling the entity to replace or to isolate.
In PCI DSS v4.0.1. 2.2.4, 2.2.5, 2.2.7