PT-2020-7329 · Pyrad · Pyrad

Published

2020-01-28

·

Updated

2022-05-05

·

CVE-2013-0294

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: pyrad versions prior to 2.1
Description: The issue is related to the use of weak random numbers in generating RADIUS authenticators and hashing passwords. This weakness makes it easier for remote attackers to obtain sensitive information via a brute force attack.
Recommendations: For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to minimize the risk of brute force attacks, such as restricting access to the RADIUS authentication system or implementing rate limiting on authentication attempts.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0294
GHSA-Q4V3-WMM6-HCRX
PYSEC-2020-211

Affected Products

Pyrad