PT-2004-3058 · Openbsd · Login Radius+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2163
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
login radius on OpenBSD versions 3.2, 3.5
Description
The issue allows remote attackers to bypass authentication by spoofing server replies due to the lack of verification of the shared secret in response packets from a RADIUS server.
Recommendations
For OpenBSD versions 3.2 and 3.5, consider disabling the login radius functionality until a patch is available to verify the shared secret in RADIUS server responses.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbsd
Login Radius