CVE-2020-15173 is a critical buffer overflow vulnerability affecting ACCEL-PPP, an implementation of various tunneling protocols. This flaw allows an unauthenticated attacker to trigger a buffer overflow by sending a specially crafted L2TP control packet with a malformed AVP, leading to a CVSS score of 9.8. The vulnerability can result in complete compromise of confidentiality, integrity, and availability of the affected system. While there is no evidence of active exploitation or public exploit code, the high community discussion indicates significant awareness, and a patch is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.12.0-92-g38b6104CPE matchmatch criteria | cpe:2.3:a:accel-ppp:accel-ppp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.