CVE-2024-3596
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 14.86% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354, CWE-924
- Affected
- freeradius/freeradius · broadcom/brocade sannav · broadcom/fabric operating system · sonicwall/sonicos
- Source
- cret@cert.org
References
- http://www.openwall.com/lists/oss-security/2024/07/09/4Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-723487.html
- https://cert-portal.siemens.com/productcert/html/ssa-794185.html
- https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/Technical Description
- https://datatracker.ietf.org/doc/html/rfc2865Technical Description
- https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdfThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014Third Party Advisory
- https://www.blastradius.fail/Technical Description
- http://www.openwall.com/lists/oss-security/2024/07/09/4Mailing List
- https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/Technical Description
- https://datatracker.ietf.org/doc/html/rfc2865Technical Description
- https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdfThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240822-0001/Third Party Advisory
- https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocolThird Party Advisory
- https://www.blastradius.fail/Technical Description
- https://www.kb.cert.org/vuls/id/456537
- https://cert-portal.siemens.com/productcert/html/ssa-364175.html
- https://cert-portal.siemens.com/productcert/html/ssa-723487.html
- https://cert-portal.siemens.com/productcert/html/ssa-770770.html
- https://cert-portal.siemens.com/productcert/html/ssa-794185.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.