CVE-2020-28194: Accel-Ppp
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.
Affected products
- Accel-Ppp Accel-Ppp: before 1.12.0-e9d369a (fixed in 1.12.0-e9d369a)
Published 2021-02-01. Last modified 2026-06-17.