peter bassill · operator
$ cve CVE-2020-28194 JSON

CVE-2020-28194

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-191
On CISA KEVno
Public exploitnone known
Published2021-02-01
Last modified2026-06-17

Affected (1)

VendorProduct
accel-pppaccel-ppp

References

→ the Explorer  ·  watch your stack  ·  NVD