CRITICAL🇵🇱 Wersja polska

CVE-2024-58250

CVSS 9.3v3.1pub. 2025-04-22upd. 2026-04-15

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

🤖 AI Analysis
How it works

The passprompt plugin, loaded by the pppd process, does not properly handle the permission context — this has been classified as CWE-426 (Untrusted Search Path), which means the possibility of substituting an untrusted component or library during the execution of a process with elevated privileges. The CVSS vector indicates local access (AV:L), no required user interaction (UI:N) and no required attacker privileges (PR:N), and the scope of the attack extends beyond the attacked component (S:C).

Impact

An attacker with local access to the system can obtain unauthorized privilege escalation, potentially taking full control of the system — with full impact on confidentiality, integrity and availability of data.

Mitigation & patch

The ppp package should be updated to version 2.5.2 or newer. A patch is available in the project repository (commit 0a66ad22e54c72690ec2a29a019767c55c5281fc). It is also recommended to track distribution updates for the ppp package.

Who is affected

The ppp package in versions before 2.5.2 — affects systems using the pppd daemon with the passprompt plugin.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References