<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:49:25.919188+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:0633</id>
    <title>ALSA-2020:0633 — Important: ppp security update</title>
    <updated>2026-10-04T03:49:26.252630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ppp, AlmaLinux:8: ppp-devel</p>
<p>The ppp packages contain the Point-to-Point Protocol (PPP) daemon and documentation for PPP support. The PPP protocol provides a method for transmitting datagrams over serial point-to-point links. PPP is usually used to dial in to an Internet Service Provider (ISP) or other organization over a modem and phone line.</p>
<p>Security Fix(es):</p>
<p>* ppp: Buffer overflow in the eap_request and eap_response functions in eap.c (CVE-2020-8597)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:0633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01026</id>
    <title>bdu:2020-01026</title>
    <updated>2026-10-04T03:49:26.252697+00:00</updated>
    <content>bdu:2020-01026</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01026"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-8597</id>
    <title>Withdrawn: BELL-CVE-2020-8597 — CVE-2020-8597 does not affect BellSoft software</title>
    <updated>2026-10-04T03:49:26.252715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-8597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-325</id>
    <title>certfr-2020-avi-325 — Une vulnérabilité a été découverte dans Hirschmann OWL. Elle permet à un
attaquant de provoquer une exécution de code a…</title>
    <updated>2026-10-04T03:49:26.252731+00:00</updated>
    <content>certfr-2020-avi-325</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-09603</id>
    <title>cnvd-2020-09603</title>
    <updated>2026-10-04T03:49:26.252746+00:00</updated>
    <content>cnvd-2020-09603</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-09603"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262405</id>
    <title>EUVD-2026-262405</title>
    <updated>2026-10-04T03:49:26.252757+00:00</updated>
    <content>EUVD-2026-262405</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8597</id>
    <title>fkie_cve-2020-8597</title>
    <updated>2026-10-04T03:49:26.252767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gw8r-xfqw-vw42</id>
    <title>GHSA-gw8r-xfqw-vw42</title>
    <updated>2026-10-04T03:49:26.252788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gw8r-xfqw-vw42"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8597</id>
    <title>gsd-2020-8597</title>
    <updated>2026-10-04T03:49:26.252802+00:00</updated>
    <content>gsd-2020-8597</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-224-04</id>
    <title>ICSA-20-224-04 — Siemens SCALANCE, RUGGEDCOM</title>
    <updated>2026-10-04T03:49:26.252812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The version of pppd shipped with this product has a vulnerability that may allow an unauthenticated remote attacker to cause a stack buffer overflow, which may allow arbitrary code execution on the target system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-224-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8597</id>
    <title>msrc_CVE-2020-8597 — eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</title>
    <updated>2026-10-04T03:49:26.252829+00:00</updated>
    <content>msrc_CVE-2020-8597</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-8597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0286-1</id>
    <title>openSUSE-SU-2020:0286-1 — Security update for ppp</title>
    <updated>2026-10-04T03:49:26.252844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ppp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0286-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0631</id>
    <title>RHSA-2020:0631 — Red Hat Security Advisory: ppp security update</title>
    <updated>2026-10-04T03:49:26.252858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ppp: Buffer overflow in the eap_request and eap_response functions in eap.c</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2022-011-02</id>
    <title>SEVD-2022-011-02 — Easergy T300</title>
    <updated>2026-10-04T03:49:26.252872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the Easergy T300 RTU (Remote Terminal Unit).
The Easergy T300 is a modular platform for medium voltage and low voltage public distribution network management.
Failure to apply the mitigations provided below may allow for arbitrary code execution, which could result in denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2022-011-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:0489-1</id>
    <title>SUSE-SU-2020:0489-1 — Security update for ppp</title>
    <updated>2026-10-04T03:49:26.252890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ppp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:0489-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8597</id>
    <title>UBUNTU-CVE-2020-8597</title>
    <updated>2026-10-04T03:49:26.252904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ppp, Ubuntu:16.04:LTS: ppp, Ubuntu:18.04:LTS: ppp, Ubuntu:20.04:LTS: ppp, Ubuntu:Pro:20.04:LTS: lwip</p>
<p>eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-018</id>
    <title>VDE-2020-018 — PHOENIX CONTACT: FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT: PPPD vulnerable to CVE-2020-8597</title>
    <updated>2026-10-04T03:49:26.252930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices are affected by a buffer overflow vulnerability within the PPP service.</p>
<p>The PPP service is not active by default, but is used commonly at TC ROUTER, TC CLOUD CLIENT.
It is also running in the following FL MGUARD and TC MGUARD configurations:</p>
<p>• Mobile data connection
• Router mode "Modem"
• Router mode "PPPoE"
• L2TP over IPsec</p>
<p>Malicious PPP peers could try to exploit the vulnerability from remote.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-020</id>
    <title>VDE-2020-020 — WAGO: PPPD in PFC100 and PFC200 Series is vulnerable to CVE-2020-8597</title>
    <updated>2026-10-04T03:49:26.252956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>WAGO PLCs uses Linux as operating system and offers the ambitious user the opportunity to make their own modifications to expand the functionality of the PLC. For this reason the pppd daemon is also part of the operating system but it is not activated in the default configuration of the WAGO firmware.</p>
<p>The reported vulnerability is only exploitable if the customer has activated the pppd daemon in his individual configuration manually. If the pppd daemon is used by the application from the customer, an unauthenticated remote attacker could cause a memory corruption in the pppd process, which may allow for arbitrary code execution, by sending an unsolicited EAP packet.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-020"/>
  </entry>
</feed>
