PT-2011-4033 · Freeradius · Freeradius
Josh Bressers
+1
·
Published
2011-08-04
·
Updated
2018-10-09
·
CVE-2011-2701
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeRADIUS version 2.1.11
Description
The issue concerns the ocsp check function in rlm eap tls.c, which does not properly parse replies from OCSP responders when OCSP is enabled. This allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.
Recommendations
For FreeRADIUS version 2.1.11, consider disabling the ocsp check function or restricting the use of the EAP-TLS protocol until a patch is available. Additionally, restrict access to the affected module to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freeradius