PT-2025-17472 · Ppp+1 · Ppp+1

Published

2025-04-22

·

Updated

2025-05-09

·

CVE-2024-58250

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ppp versions prior to 2.5.2
Description The passprompt plugin in pppd mishandles privileges. This issue affects versions of PPP prior to 2.5.2.
Recommendations For versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the passprompt plugin until a patch is available. Restrict access to the pppd component to minimize the risk of exploitation.

Fix

LPE

Untrusted Search Path

Weakness Enumeration

Related Identifiers

AZL-60894
AZL-61768
CVE-2024-58250
OESA-2025-1479

Affected Products

Debian
Ppp