CVE-2020-7465: Critical severity mpd vulnerability
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-7465.
What is the severity of CVE-2020-7465?
CVE-2020-7465 has a severity rating of 9.8 (critical).
What is the affected software for CVE-2020-7465?
The affected software for CVE-2020-7465 includes MPD (version up to exclusive 5.9) and Stormshield Network Security (version between inclusive 4.0.0 and exclusive 4.3.17, as well as version 4.4.0).
What is the description of CVE-2020-7465?
CVE-2020-7465 is a vulnerability in the L2TP implementation of MPD before 5.9 that allows a remote attacker to execute arbitrary code or cause a denial of service through a specifically crafted L2TP control packet with AVP Q.931 Cause Code, resulting in memory corruption.
How can I fix CVE-2020-7465?
To fix CVE-2020-7465, it is recommended to update MPD to version 5.9 or higher and Stormshield Network Security to a version higher than 4.3.17, as well as apply any patches or security updates provided by the vendors.