RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
Vulnerability Description
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3596
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Thanks to Sharon Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl who researched and reported this vulnerability
References
- https://datatracker.ietf.org/doc/html/rfc2865
- https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/
- https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf
- https://www.blastradius.fail/
- http://www.openwall.com/lists/oss-security/2024/07/09/4
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014
- https://cert-portal.siemens.com/productcert/html/ssa-794185.html
- https://cert-portal.siemens.com/productcert/html/ssa-723487.html
More from IETF
View All →Affected Vendor
IETF
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.