Accel PPP is a narrowly scoped access server and PPP (Point-to-Point Protocol) daemon used in carrier and ISP network infrastructure, where it handles authentication, session management, and protocol mediation for dial-up and broadband subscriber access. The vendor's disclosed vulnerabilities reflect the protocol-handling and authentication-layer complexity inherent to network access systems, and the product's role in managing subscriber connections makes it a recurring fixture in carrier deployments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accel Ppp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24704CRITICAL The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.int | Feb 14, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-28194CRITICAL Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker c | Feb 1, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-0982CRITICAL The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->bu | Mar 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-15173CRITICAL In ACCEL-PPP (an implementation of PPTP/PPPoE/L2TP/SSTP), there is a buffer overflow when receiving an l2tp control packet ith an AVP which type is a string and no hidden flags, le | Sep 9, 2020 | 9.8 | 29 | NO | NO |
CVE-2021-42870HIGH ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request. | May 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-24705CRITICAL The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and o | Feb 14, 2022 | 9.8 | 24 | NO | NO |
CVE-2021-42054HIGH ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication. | Oct 7, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accel Ppp.
Media articles that mention a CVE ID that affects a product developed by Accel Ppp — matched by CVE ID, not by vendor name.