Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenBSD Vulnerability Bypasses PAP Authentication

OpenBSD Vulnerability Bypasses PAP Authentication

Posted on June 17, 2026 By CWS

A critical flaw has been identified in the OpenBSD networking stack, allowing attackers to bypass its Password Authentication Protocol (PAP) entirely. This vulnerability, present since 1999, was recently disclosed and poses significant security risks.

Vulnerability Details

The issue is located in the sppp_pap_input() function of OpenBSD’s sppp(4) subsystem, which is responsible for handling synchronous PPP links within PPPoE connections. During the authentication phase using PAP, user credentials are meant to be verified before a network session is established. However, a fundamental flaw in this logic has persisted since its inception.

The vulnerability arises from improper management of length fields during credential validation. The function bcmp() was used for comparing username and password fields, relying on lengths directly from incoming PAP frames. Zero-length credentials could bypass these checks, resulting in unauthorized access.

Impact and Exploitation

This flaw allows attackers to completely bypass authentication, gaining access to PPP sessions without valid credentials. A related risk involves kernel heap overreads, as the bcmp() function could read beyond allocated memory when handling oversized credentials, exposing adjacent data.

The vulnerability is accessible through the PPPoE data path, requiring no valid credentials. An attacker, running a rogue PPPoE server within the same broadcast domain, can exploit this weakness to masquerade as a legitimate server. This enables full session establishment, including IP configuration and ICMP communication, demonstrating the exploit’s feasibility.

Resolution and Recommendations

The original code came from FreeBSD, with the flaw remaining unnoticed for 27 years despite various updates. A fix has been implemented, mirroring safer patterns from the CHAP handler by incorporating exact-length pre-checks before any bcmp() calls. These checks prevent zero-length and oversized inputs from being processed.

According to Argus, the vulnerability was disclosed on June 12, 2026, and a patch was released within two days. Organizations utilizing OpenBSD, especially where PPPoE authentication is critical, should apply the latest patches promptly to mitigate potential threats.

This incident underscores the importance of regular security audits and updates to prevent legacy vulnerabilities from being exploited.

Cyber Security News Tags:authentication bypass, authentication protocol, Cybersecurity, kernel vulnerability, network protocol, network security, Networking, OpenBSD, PAP authentication, PPPoE, security patch, software update, system security, Vulnerability, zero-day exploit

Post navigation

Previous Post: Optimizing URL Phishing Triage with Browser Insights
Next Post: Hackers Exploit ClickFix to Deploy Remote Access Tools

Related Posts

Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory Cyber Security News
Indian Bank Alerts on LPG Payment Scams Threatening Accounts Indian Bank Alerts on LPG Payment Scams Threatening Accounts Cyber Security News
28,000 Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online 28,000 Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online Cyber Security News
TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses Cyber Security News
FBI Warns of US Govt Officials Impersonated in Malicious Message Campaign FBI Warns of US Govt Officials Impersonated in Malicious Message Campaign Cyber Security News
CISA Warns Of Rapid7 Velociraptor Vulnerability Exploited in Ransomware Attacks CISA Warns Of Rapid7 Velociraptor Vulnerability Exploited in Ransomware Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Thousands of Fortinet Firewalls Targeted in Global Cyber Attack
  • Hackers Exploit ClickFix to Deploy Remote Access Tools
  • OpenBSD Vulnerability Bypasses PAP Authentication
  • Optimizing URL Phishing Triage with Browser Insights
  • AI-Driven Phishing Threats Rise, SpyCloud Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Thousands of Fortinet Firewalls Targeted in Global Cyber Attack
  • Hackers Exploit ClickFix to Deploy Remote Access Tools
  • OpenBSD Vulnerability Bypasses PAP Authentication
  • Optimizing URL Phishing Triage with Browser Insights
  • AI-Driven Phishing Threats Rise, SpyCloud Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark