Vulnerabilities > CVE-2020-7465 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mpd-project
stormshield
CWE-787
critical

Summary

The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).

Vulnerable Configurations

Part Description Count
Application
Mpd_Project
30
Application
Stormshield
34

Common Weakness Enumeration (CWE)