Impact
A local user who has permission to create VPN connections can craft a VPN username that contains a double‑quote character or whitespace to terminate the current pppd options quoting context. The attacker then injects a pppd plugin directive that causes the privileged pppd process to load an attacker‑controlled shared object. This allows execution of arbitrary code with root privileges, giving the attacker full control over the system. The weakness is a form of input‑validation flaw where untrusted user input is used to construct privileged commands (CWE‑88).
Affected Systems
NetworkManager‑l2tp versions up to and including 1.52.4 are affected. The vulnerability was fixed in release 1.52.6. All systems running the vulnerable package are at risk and must be identified and updated.
Risk and Exploitability
The CVSS base score is 8.5, indicating high severity. EPSS is not available, so the exploitation probability is not quantified, but the lack of a KEV listing suggests no widespread exploitation yet. Attackers require local user access with the ability to create VPN connections; the exploit is local and does not require network exposure. Once the injected username is created, the compromised pppd instance runs as root, providing a straightforward path to arbitrary code execution.
OpenCVE Enrichment
Debian DSA