CVE-2014-4943 describes a local privilege escalation vulnerability in the PPPoL2TP feature of the Linux kernel (through version 3.15.6), affecting various distributions like Debian, Red Hat, and SUSE. This flaw, rated with a CVSS score of 6.9, allows a local attacker to gain full control of the system with medium attack complexity due to data-structure differences between socket types. While not listed in CISA's KEV catalog, a Proof-of-Concept exploit exists on ExploitDB, and it has seen some community discussion, though no active exploitation or media coverage has been reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.23, < 3.2.62CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.102CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.10.52CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.27CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.14.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.