PT-2021-4266 · Unknown · Radsecproxy

Haya Shulman

+1

·

Published

2021-05-28

·

Updated

2022-08-19

·

CVE-2021-32642

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions radsecproxy (affected versions not specified)
Description The issue is related to missing input validation in radsecproxy's naptr-eduroam.sh and radsec-dynsrv.sh scripts, which can lead to configuration injection via crafted radsec peer discovery DNS records. This can result in information disclosure, denial of service, and redirection of the Radius connection to a non-authenticated server, leading to non-authenticated network access.
Recommendations To resolve the issue, update the example scripts to the versions available in the master branch or 1.9 release. Note that these scripts are not part of the installation package and must be updated manually. The updated scripts can be used with any version of radsecproxy. As a temporary workaround, consider restricting the use of the vulnerable scripts until the updated versions are applied.

Fix

Special Elements Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-04874
CVE-2021-32642
GHSA-56GW-9RJ9-55RC

Affected Products

Radsecproxy