PT-2004-3058 · Openbsd · Login Radius+1

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2163

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions login radius on OpenBSD versions 3.2, 3.5
Description The issue allows remote attackers to bypass authentication by spoofing server replies due to the lack of verification of the shared secret in response packets from a RADIUS server.
Recommendations For OpenBSD versions 3.2 and 3.5, consider disabling the login radius functionality until a patch is available to verify the shared secret in RADIUS server responses.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2163

Produtos afetados

Openbsd
Login Radius