CVE-2024-3596: RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Classification

CVE ID: CVE-2024-3596

Affected Products

Vendor: IETF

Product: RFC

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.16% (probability of being exploited)

EPSS Percentile: 0.53677 (how common is this exploit)

EPSS Date: 2025-03-10 (when was this score calculated)

Timeline