PT-2004-3058 · Openbsd · Login Radius+1

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2163

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions login radius on OpenBSD versions 3.2, 3.5
Description The issue allows remote attackers to bypass authentication by spoofing server replies due to the lack of verification of the shared secret in response packets from a RADIUS server.
Recommendations For OpenBSD versions 3.2 and 3.5, consider disabling the login radius functionality until a patch is available to verify the shared secret in RADIUS server responses.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2163

Affected Products

Openbsd
Login Radius