Point To Point Protocol
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
6
Total CVEs
More Total CVEs than 83% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Point To Point Protocol over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Feb 3, 2020
2,367 days ago
CVE Severity & Scoring
Point To Point Protocol6 CVEs
17%
50%
33%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (33.3%)
Unknown4 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (33.3%)
High0 (0.0%)
Unknown4 (66.7%)
User Interaction
None2 (33.3%)
Unknown4 (66.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (33.3%)
Unknown4 (66.7%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8597CRITICAL eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | Feb 3, 2020 | 9.8 | 40 | NO | NO |
CVE-2018-11574CRITICAL Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This | Jun 14, 2018 | 9.8 | 29 | NO | NO |
CVE-2014-3158HIGH Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options | Nov 15, 2014 | 7.5 | 20 | NO | NO |
CVE-2004-2695HIGH SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL | Dec 31, 2004 | 7.5 | 20 | NO | NO |
CVE-2006-2194HIGH The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setui | Jul 5, 2006 | 7.2 | 18 | NO | NO |
CVE-2015-3310MEDIUM Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attacker | Apr 24, 2015 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Point To Point Protocol
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4.1 | 1 | 7.5 | 1.9% | 0 | 0 |