CVE-2020-8597 is a stack-based buffer overflow in pppd (Point-to-Point Protocol Daemon) affecting versions 2.4.2 through 2.4.8. The flaw is in EAP packet processing in eap.c, specifically in the eap_request and eap_response functions, where the rhostname buffer can be overflowed while handling crafted or unsolicited Extensible Authentication Protocol (EAP) packets. A remote attacker can trigger memory corruption by sending malicious EAP input to a vulnerable ppp client or server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a minimal Python proof-of-concept for CVE-2020-8597 (PPP/pppd PPPoE/EAP parsing issue) plus a README with lab setup notes. Structure: - `PoC.py`: Uses Scapy to sniff exactly one PPPoE Session packet (`filter="pppoes"`) on interface `ens33` to extract the active PPPoE session-id. It then crafts and transmits a raw Ethernet frame via a Linux `AF_PACKET`/`SOCK_RAW` socket. The frame is PPPoE Session (Ethertype 0x8864) carrying PPP protocol 0xC227 (EAP) and an EAP-MD5-Challenge-like payload with a large trailing buffer (`'A'... + 'a'*0x100`). Source/destination MAC addresses are hardcoded to VMware OUI values, indicating a VM lab. - `README.md`: Describes setting up a PPPoE server/client on Ubuntu, enabling debug logging in `/etc/ppp/pppoe-server-options` and writing logs to `/var/log/pppoe-server-log`, and shows a crash screenshot. Exploit capability: - Network-adjacent (same broadcast domain) denial-of-service by injecting a malformed/oversized PPPoE/PPP/EAP frame after learning the session-id. No post-exploitation or code execution payload is present; it is a crash PoC.
This repository contains two Python scripts related to PPPoE (Point-to-Point Protocol over Ethernet) and the exploitation of CVE-2020-8597 in pppd (PPP Daemon). The main exploit script is 'PoC.py', which crafts and sends a malicious PPPoE packet containing a MIPS reverse shell payload to a target running a vulnerable version of pppd. The payload is delivered via a ROP chain embedded in an EAP-MD5 authentication packet, ultimately granting the attacker a reverse shell on the target (connecting to 192.168.31.111:1111). The script uses Scapy for low-level packet crafting and network interaction. The 'PPPoE_Simulator.py' script simulates a PPPoE server, handling various stages of the PPPoE and PPP protocol, and can be used for testing or as a helper tool. The exploit requires network access to the target and is operational, with a hardcoded payload. The repository is focused, with no extraneous files, and is written entirely in Python.
This repository contains a proof-of-concept exploit for CVE-2020-8597, a vulnerability in the PPP daemon (pppd) used for Point-to-Point Protocol connections, commonly over PPPoE. The main file, PoC.py, is a Python script that uses Scapy and raw sockets to sniff for a PPPoE session and then sends a specially crafted EAP-MD5 response packet with a large payload. The exploit is designed to be run in a virtualized environment where both PPPoE server and client are present on the same network interface (ens33). The README provides setup instructions for both server and client, as well as references for further information. The exploit targets the network stack and requires access to the PPPoE traffic, making it a network-based attack. The payload is a raw network packet intended to trigger a crash or buffer overflow in the target pppd process. No hardcoded IP addresses or domain names are present, but specific file paths for configuration and logging are mentioned in the setup instructions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.