CVE-2024-3596
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
- Affected products
- Almalinux, Astra Linux, Centos, Check Point Gaia, Debian, Fortios, Freeradius, Linuxmint
- Freeradius
- < 3.0.27
- Fix
- Available
- CVSS 3.1
- 9.0 CRITICAL
- EPSS
- 14.9% (96th percentile)
- Weakness
- CWE-354, CWE-924
- NVD status
- Modified
- Published
- 2024-07-09
CVE-2024-3596 at NVD
2 known exploits for CVE-2024-3596
Proof-of-concept code and exploit modules indexed by Sploitus