PT-2019-6844 · Pyrad+1 · Pyrad+1

Nathaniel Mccallum

·

Published

2019-12-09

·

Updated

2022-05-05

·

CVE-2013-0342

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pyrad versions prior to 2.1
Description The issue concerns the CreateID function in packet.py, which uses sequential packet IDs. This predictability makes it easier for remote attackers to spoof packets.
Recommendations For versions prior to 2.1, update to version 2.1 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0342
GHSA-W4PX-9PGM-P2F3
PYSEC-2019-154

Affected Products

Debian
Pyrad