Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15173

Опубликовано: 09 сент. 2020
Источник: nvd
CVSS3: 8.2
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In ACCEL-PPP (an implementation of PPTP/PPPoE/L2TP/SSTP), there is a buffer overflow when receiving an l2tp control packet ith an AVP which type is a string and no hidden flags, length set to less than 6. If your application is used in open networks or there are untrusted nodes in the network it is highly recommended to apply the patch. The problem was patched with commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b As a workaround changes of commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b can be applied to older versions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:accel-ppp:accel-ppp:*:*:*:*:*:*:*:*
Версия до 1.12.0-92-g38b6104 (включая)

EPSS

Процентиль: 64%
0.00459
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119
CWE-120

EPSS

Процентиль: 64%
0.00459
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119
CWE-120