PT-2020-7329 · Pyrad · Pyrad
Published
2020-01-28
·
Updated
2022-05-05
·
CVE-2013-0294
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
pyrad versions prior to 2.1
Description:
The issue is related to the use of weak random numbers in generating RADIUS authenticators and hashing passwords. This weakness makes it easier for remote attackers to obtain sensitive information via a brute force attack.
Recommendations:
For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to minimize the risk of brute force attacks, such as restricting access to the RADIUS authentication system or implementing rate limiting on authentication attempts.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyrad