<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:21:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:0633 — Important: ppp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:0633</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ppp, AlmaLinux:8: ppp-devel&lt;/p&gt;
&lt;p&gt;The ppp packages contain the Point-to-Point Protocol (PPP) daemon and documentation for PPP support. The PPP protocol provides a method for transmitting datagrams over serial point-to-point links. PPP is usually used to dial in to an Internet Service Provider (ISP) or other organization over a modem and phone line.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ppp: Buffer overflow in the eap_request and eap_response functions in eap.c (CVE-2020-8597)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ppp, AlmaLinux:8: ppp-devel&lt;/p&gt;
&lt;p&gt;The ppp packages contain the Point-to-Point Protocol (PPP) daemon and documentation for PPP support. The PPP protocol provides a method for transmitting datagrams over serial point-to-point links. PPP is usually used to dial in to an Internet Service Provider (ISP) or other organization over a modem and phone line.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ppp: Buffer overflow in the eap_request and eap_response functions in eap.c (CVE-2020-8597)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:0633</guid>
    </item>
    <item>
      <title>bdu:2020-01026</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01026</link>
      <description>bdu:2020-01026</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01026</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-8597 — CVE-2020-8597 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-8597</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-8597</guid>
    </item>
    <item>
      <title>certfr-2020-avi-325 — Une vulnérabilité a été découverte dans Hirschmann OWL. Elle permet à un
attaquant de provoquer une exécution de code a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-325</link>
      <description>certfr-2020-avi-325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-325</guid>
    </item>
    <item>
      <title>cnvd-2020-09603</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-09603</link>
      <description>cnvd-2020-09603</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-09603</guid>
    </item>
    <item>
      <title>EUVD-2026-262405</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262405</link>
      <description>EUVD-2026-262405</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262405</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8597</link>
      <description>&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8597</guid>
    </item>
    <item>
      <title>GHSA-gw8r-xfqw-vw42</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gw8r-xfqw-vw42</link>
      <description>&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gw8r-xfqw-vw42</guid>
    </item>
    <item>
      <title>gsd-2020-8597</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8597</link>
      <description>gsd-2020-8597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8597</guid>
    </item>
    <item>
      <title>ICSA-20-224-04 — Siemens SCALANCE, RUGGEDCOM</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-224-04</link>
      <description>&lt;p&gt;The version of pppd shipped with this product has a vulnerability that may allow an unauthenticated remote attacker to cause a stack buffer overflow, which may allow arbitrary code execution on the target system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The version of pppd shipped with this product has a vulnerability that may allow an unauthenticated remote attacker to cause a stack buffer overflow, which may allow arbitrary code execution on the target system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-224-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-8597 — eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8597</link>
      <description>msrc_CVE-2020-8597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-8597</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0286-1 — Security update for ppp</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0286-1</link>
      <description>&lt;p&gt;Security update for ppp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ppp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0286-1</guid>
    </item>
    <item>
      <title>RHSA-2020:0631 — Red Hat Security Advisory: ppp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0631</link>
      <description>&lt;p&gt;ppp: Buffer overflow in the eap_request and eap_response functions in eap.c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ppp: Buffer overflow in the eap_request and eap_response functions in eap.c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0631</guid>
    </item>
    <item>
      <title>SEVD-2022-011-02 — Easergy T300</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2022-011-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Easergy T300 RTU (Remote Terminal Unit).&#13;
The Easergy T300 is a modular platform for medium voltage and low voltage public distribution network management.&#13;
Failure to apply the mitigations provided below may allow for arbitrary code execution, which could result in denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Easergy T300 RTU (Remote Terminal Unit).&#13;
The Easergy T300 is a modular platform for medium voltage and low voltage public distribution network management.&#13;
Failure to apply the mitigations provided below may allow for arbitrary code execution, which could result in denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2022-011-02</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:0489-1 — Security update for ppp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:0489-1</link>
      <description>&lt;p&gt;Security update for ppp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ppp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:0489-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8597</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ppp, Ubuntu:16.04:LTS: ppp, Ubuntu:18.04:LTS: ppp, Ubuntu:20.04:LTS: ppp, Ubuntu:Pro:20.04:LTS: lwip&lt;/p&gt;
&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ppp, Ubuntu:16.04:LTS: ppp, Ubuntu:18.04:LTS: ppp, Ubuntu:20.04:LTS: ppp, Ubuntu:Pro:20.04:LTS: lwip&lt;/p&gt;
&lt;p&gt;eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8597</guid>
    </item>
    <item>
      <title>VDE-2020-018 — PHOENIX CONTACT: FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT: PPPD vulnerable to CVE-2020-8597</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-018</link>
      <description>&lt;p&gt;FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices are affected by a buffer overflow vulnerability within the PPP service.&lt;/p&gt;
&lt;p&gt;The PPP service is not active by default, but is used commonly at TC ROUTER, TC CLOUD CLIENT.
It is also running in the following FL MGUARD and TC MGUARD configurations:&lt;/p&gt;
&lt;p&gt;• Mobile data connection
• Router mode &amp;#34;Modem&amp;#34;
• Router mode &amp;#34;PPPoE&amp;#34;
• L2TP over IPsec&lt;/p&gt;
&lt;p&gt;Malicious PPP peers could try to exploit the vulnerability from remote.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices are affected by a buffer overflow vulnerability within the PPP service.&lt;/p&gt;
&lt;p&gt;The PPP service is not active by default, but is used commonly at TC ROUTER, TC CLOUD CLIENT.
It is also running in the following FL MGUARD and TC MGUARD configurations:&lt;/p&gt;
&lt;p&gt;• Mobile data connection
• Router mode &amp;#34;Modem&amp;#34;
• Router mode &amp;#34;PPPoE&amp;#34;
• L2TP over IPsec&lt;/p&gt;
&lt;p&gt;Malicious PPP peers could try to exploit the vulnerability from remote.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-018</guid>
    </item>
    <item>
      <title>VDE-2020-020 — WAGO: PPPD in PFC100 and PFC200 Series is vulnerable to CVE-2020-8597</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-020</link>
      <description>&lt;p&gt;WAGO PLCs uses Linux as operating system and offers the ambitious user the opportunity to make their own modifications to expand the functionality of the PLC. For this reason the pppd daemon is also part of the operating system but it is not activated in the default configuration of the WAGO firmware.&lt;/p&gt;
&lt;p&gt;The reported vulnerability is only exploitable if the customer has activated the pppd daemon in his individual configuration manually. If the pppd daemon is used by the application from the customer, an unauthenticated remote attacker could cause a memory corruption in the pppd process, which may allow for arbitrary code execution, by sending an unsolicited EAP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WAGO PLCs uses Linux as operating system and offers the ambitious user the opportunity to make their own modifications to expand the functionality of the PLC. For this reason the pppd daemon is also part of the operating system but it is not activated in the default configuration of the WAGO firmware.&lt;/p&gt;
&lt;p&gt;The reported vulnerability is only exploitable if the customer has activated the pppd daemon in his individual configuration manually. If the pppd daemon is used by the application from the customer, an unauthenticated remote attacker could cause a memory corruption in the pppd process, which may allow for arbitrary code execution, by sending an unsolicited EAP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-020</guid>
    </item>
  </channel>
</rss>
