8.3

CVE-2026-55706

Exploit
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenbsdOpenbsd Version <= 7.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.3 1.6 6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
MITRE 5.8 1.6 3.7
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
Third Party Advisory
Exploit
https://www.openwall.com/lists/oss-security/2026/06/16/9
Patch
Third Party Advisory
Exploit
Mailing List
https://github.com/openbsd/src/commit/076e2b1c1fc4ac0883a72d3544131ad5cee7adf8
Patch
https://blog.argus-systems.ai/blog/poc-001-pap-bypass.py
Exploit