PT-2023-14045 · Unknown+6 · Freeradius+5

Alandekok

·

Published

2022-04-22

·

Updated

2025-06-26

·

CVE-2022-41859

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions freeradius (affected versions not specified)
Description The EAP-PWD function compute password element() in freeradius leaks information about the password, allowing an attacker to substantially reduce the size of an offline dictionary attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2166
ALSA-2023:2870
CESA-2023_2870
CVE-2022-41859
DLA-3342-1
DLA-4232-1
MGASA-2022-0482
OESA-2023-1953
OESA-2023-1954
OESA-2023-1955
OESA-2023-1956
OPENSUSE-SU-2022_4622-1
OPENSUSE-SU-2022_4626-1
OPENSUSE-SU-2024:13386-1
RHSA-2023:2166
RHSA-2023:2870
RHSA-2023_2166
RHSA-2023_2870
SUSE-SU-2022:4620-1
SUSE-SU-2022:4621-1
SUSE-SU-2022:4622-1
SUSE-SU-2022:4626-1
SUSE-SU-2022_4620-1
SUSE-SU-2022_4621-1
SUSE-SU-2022_4622-1
SUSE-SU-2022_4626-1
SUSE-SU-2023:0124-1
SUSE-SU-2023:0135-1
SUSE-SU-2023_0124-1
SUSE-SU-2023_0135-1

Affected Products

Almalinux
Centos
Debian
Freeradius
Red Hat
Suse