PT-2023-14045 · Unknown+6 · Freeradius+5

Alandekok

·

Publicado

2022-04-22

·

Atualizado

2025-06-26

·

CVE-2022-41859

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions freeradius (affected versions not specified)
Description The EAP-PWD function compute password element() in freeradius leaks information about the password, allowing an attacker to substantially reduce the size of an offline dictionary attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:2166
ALSA-2023:2870
CESA-2023_2870
CVE-2022-41859
DLA-3342-1
DLA-4232-1
MGASA-2022-0482
OESA-2023-1953
OESA-2023-1954
OESA-2023-1955
OESA-2023-1956
OPENSUSE-SU-2022_4622-1
OPENSUSE-SU-2022_4626-1
OPENSUSE-SU-2024:13386-1
RHSA-2023:2166
RHSA-2023:2870
RHSA-2023_2166
RHSA-2023_2870
SUSE-SU-2022:4620-1
SUSE-SU-2022:4621-1
SUSE-SU-2022:4622-1
SUSE-SU-2022:4626-1
SUSE-SU-2022_4620-1
SUSE-SU-2022_4621-1
SUSE-SU-2022_4622-1
SUSE-SU-2022_4626-1
SUSE-SU-2023:0124-1
SUSE-SU-2023:0135-1
SUSE-SU-2023_0124-1
SUSE-SU-2023_0135-1

Produtos afetados

Almalinux
Centos
Debian
Freeradius
Red Hat
Suse