The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).
2020-10-06T14:15:13.167
2024-11-21T05:37:11.953
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mpd_project | mpd | < 5.9 | Yes |
| Application | stormshield | stormshield_network_security | < 4.3.17 | Yes |
| Application | stormshield | stormshield_network_security | 4.4.0 | Yes |