CVE-2017-9148
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- freeradius/freeradius
- Source
- cve@mitre.org
References
- http://freeradius.org/security.htmlNot Applicable
- http://seclists.org/oss-sec/2017/q2/422Mailing List, VDB Entry
- http://www.securityfocus.com/bid/98734Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038576
- https://access.redhat.com/errata/RHSA-2017:1581
- https://security.gentoo.org/glsa/201706-27
- http://freeradius.org/security.htmlNot Applicable
- http://seclists.org/oss-sec/2017/q2/422Mailing List, VDB Entry
- http://www.securityfocus.com/bid/98734Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038576
- https://access.redhat.com/errata/RHSA-2017:1581
- https://security.gentoo.org/glsa/201706-27
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.