PT-2024-4668 · Palo Alto Networks+13 · Pan-Os+13

Adam Suhl

+6

·

Published

2024-07-09

·

Updated

2026-04-10

·

CVE-2024-3596

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: RADIUS Protocol (affected versions not specified) FreeRadius (affected versions not specified) Palo Alto Networks PAN-OS (affected versions not specified) eduMFA prior version 2.2.0
Description: The RADIUS protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. This vulnerability allows an attacker performing a meddler-in-the-middle attack between a RADIUS client and server to bypass authentication and escalate privileges. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For RADIUS Protocol: Update the protocol to use a secure authentication method, such as a hashed message authentication code (HMAC) or a digital signature. For FreeRadius: Update to a version that includes a fix for this vulnerability. For Palo Alto Networks PAN-OS: Update the RADIUS server profile to use a secure authentication protocol, such as TLS, and ensure that CHAP or PAP is not used unless encapsulated by an encrypted tunnel. For eduMFA: Update to version 2.2.0 or later. As a temporary workaround, consider restricting access to the RADIUS server and limiting the use of vulnerable protocols, such as CHAP or PAP, until a patch is available.

Exploit

Fix

LPE

Improper Verification of Cryptographic Signature

Information Disclosure

Related Identifiers

ALSA-2024:4935
ALSA-2024:4936
ALSA-2024:8860
ALSA-2024:9474
ALSA-2024_4935
ALSA-2024_4936
ALSA-2024_8860
ALSA-2024_9474
BDU:2024-05180
CESA-2024_4936
CESA-2024_8860
CVE-2024-3596
ELSA-2024-4911
ELSA-2024-4935
ELSA-2024-4936
ELSA-2024-8788
ELSA-2024-8860
ELSA-2024-9474
GHSA-VHMJ-5Q9R-MM9G
INFSA-2024_4935
INFSA-2024_4936
INFSA-2024_8860
INFSA-2024_9474
MGASA-2024-0264
MGASA-2024-0385
OESA-2024-1878
OESA-2024-2380
OPENSUSE-SU-2024_2359-1
OPENSUSE-SU-2024_2366-1
OPENSUSE-SU-2026:10528-1
RHSA-2024:4826
RHSA-2024:4828
RHSA-2024:4829
RHSA-2024:4874
RHSA-2024:4911
RHSA-2024:4912
RHSA-2024:4913
RHSA-2024:4935
RHSA-2024:4936
RHSA-2024:8461
RHSA-2024:8577
RHSA-2024:8788
RHSA-2024:8789
RHSA-2024:8791
RHSA-2024:8792
RHSA-2024:8794
RHSA-2024:8860
RHSA-2024:9474
RHSA-2024:9547
RHSA-2024_4935
RHSA-2024_4936
RHSA-2024_8860
RHSA-2024_9474
RLSA-2024:4935
RLSA-2024:4936
RLSA-2024:8860
RLSA-2024:9474
RLSA-2024_4935
RLSA-2024_4936
RLSA-2024_8860
RLSA-2024_9474
ROSA-SA-2024-2509
ROSA-SA-2025-2559
SUSE-SU-2024:2359-1
SUSE-SU-2024:2361-1
SUSE-SU-2024:2366-1
SUSE-SU-2024:2367-1
SUSE-SU-2024_2359-1
SUSE-SU-2024_2361-1
SUSE-SU-2024_2366-1
SUSE-SU-2024_2367-1
USN-7055-1
USN-7257-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Fortios
Freeradius
Linuxmint
Pan-Os
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Windows