vendor:
PPPoE
by:
dethy
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: PPPoE
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, NetBSD
2000
PPPoE Denial of Service Vulnerability
PPPoE contains a possibly remotely exploitable denial of service vulnerability in its handling of TCP packets when the Clamp_MSS option is used. If PPPoE recieves a malformed TCP packet with a 'zero-length option', PPPoE will go into an infinite loop. As a result, the ppp connection being supported by PPPoE will time out and be terminated.
Mitigation:
Upgrade to the latest version of PPPoE