Security Advisory

CVE-2020-28194

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-01 13:13:47
Last updated 2024-08-04 16:33:58
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.