27-Year-Old OpenBSD Vulnerability Exposed: Remote Auth Bypass Disclosed
Article Content
- •A critical vulnerability in OpenBSD's PAP authentication has existed for 27 years.
- •Attackers can bypass authentication and intercept PPPoE traffic without credentials.
- •OpenBSD has released a patch to address the vulnerability, urging immediate application.
A vulnerability in OpenBSD's networking stack has been disclosed, allowing attackers to bypass PAP authentication due to a logic flaw in the sppp_pap_input() function. This flaw, present since the import from FreeBSD in July 1999, enables attackers to intercept and read PPPoE traffic without credentials. The vulnerability affects systems relying on the Password Authentication Protocol (PAP) during the authentication phase. OpenBSD has released a patch to address this issue. The vulnerability has persisted through nearly three decades of system updates. Argus-Systems discovered the flaw, which is now classified as a critical security risk. Users of OpenBSD are urged to apply the patch immediately to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…