By vendor
Openbsd vulnerabilities
Known CVEs affecting Openbsd products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-55706MEDIUM 5.8
A flaw in OpenBSD's serialized-line-protocol (SPPP) implementation allows attackers on an adjacent network to bypass authentication by supplying specially crafted zero-length values during the PAP (Password Authentication Protocol) exchange. The vulnerability resides in the input validation logic of the sppp_pap_input function and requires local network access but no user interaction to exploit. Successful exploitation leads to unauthorized access to authenticated services, potentially compromising confidentiality, integrity, and availability.