VulnerabilityModified
CVE-2013-0294
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
MEDIUM 5.9EPSS 2.86%
Does this matter?
Lower severity and a low EPSS score (2.86%). Track it; it rarely justifies an emergency change on its own.
Description
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.86% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- pyrad project/pyrad · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115677.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115705.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116567.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/15/13Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/57984Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=911682Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82133Third Party Advisory, VDB Entry
- https://github.com/wichert/pyrad/commit/38f74b36814ca5b1a27d9898141126af4953bee5Patch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115677.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115705.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116567.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/15/13Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/57984Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=911682Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82133Third Party Advisory, VDB Entry
- https://github.com/wichert/pyrad/commit/38f74b36814ca5b1a27d9898141126af4953bee5Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.