PT-2004-3058 · Openbsd · Login Radius+1
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2163
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
login radius on OpenBSD versions 3.2, 3.5
Description
The issue allows remote attackers to bypass authentication by spoofing server replies due to the lack of verification of the shared secret in response packets from a RADIUS server.
Recommendations
For OpenBSD versions 3.2 and 3.5, consider disabling the login radius functionality until a patch is available to verify the shared secret in RADIUS server responses.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openbsd
Login Radius