<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:08:45 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4935 — Important: freeradius security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4935</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: freeradius, AlmaLinux:9: freeradius-devel, AlmaLinux:9: freeradius-doc, AlmaLinux:9: freeradius-krb5, AlmaLinux:9: freeradius-ldap, AlmaLinux:9: freeradius-mysql, AlmaLinux:9: freeradius-perl, AlmaLinux:9: freeradius-postgresql, AlmaLinux:9: freeradius-rest, AlmaLinux:9: freeradius-sqlite and 3 more&lt;/p&gt;
&lt;p&gt;FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freeradius: forgery attack (CVE-2024-3596)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: freeradius, AlmaLinux:9: freeradius-devel, AlmaLinux:9: freeradius-doc, AlmaLinux:9: freeradius-krb5, AlmaLinux:9: freeradius-ldap, AlmaLinux:9: freeradius-mysql, AlmaLinux:9: freeradius-perl, AlmaLinux:9: freeradius-postgresql, AlmaLinux:9: freeradius-rest, AlmaLinux:9: freeradius-sqlite and 3 more&lt;/p&gt;
&lt;p&gt;FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freeradius: forgery attack (CVE-2024-3596)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4935</guid>
    </item>
    <item>
      <title>bdu:2024-05180</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05180</link>
      <description>bdu:2024-05180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05180</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0550 — Une vulnérabilité a été découverte dans le protocole RADIUS. Elle permet à un attaquant de provoquer un contournement d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0550</link>
      <description>certfr-2024-avi-0550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0550</guid>
    </item>
    <item>
      <title>cisco-sa-radius-spoofing-july-2024-87cCDwZ3 — RADIUS Protocol Spoofing Vulnerability (Blast-RADIUS): July 2024</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-radius-spoofing-july-2024-87ccdwz3</link>
      <description>&lt;p&gt;On July 7, 2024, security researchers disclosed the following vulnerability in the RADIUS protocol:&#13;
&#13;
CVE-2024-3596: RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by an on-path attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&#13;
This vulnerability may impact any RADIUS client and server. For a description of this vulnerability, see VU#456537: RADIUS protocol susceptible to forgery attacks [&amp;#34;https://www.kb.cert.org/vuls/id/456537&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On July 7, 2024, security researchers disclosed the following vulnerability in the RADIUS protocol:&#13;
&#13;
CVE-2024-3596: RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by an on-path attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&#13;
This vulnerability may impact any RADIUS client and server. For a description of this vulnerability, see VU#456537: RADIUS protocol susceptible to forgery attacks [&amp;#34;https://www.kb.cert.org/vuls/id/456537&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-radius-spoofing-july-2024-87ccdwz3</guid>
    </item>
    <item>
      <title>cnvd-2024-33450</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-33450</link>
      <description>cnvd-2024-33450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-33450</guid>
    </item>
    <item>
      <title>ESSA-2024:0650 — security update for freeradius</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2024:0650</link>
      <description>&lt;p&gt;security update for freeradius&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for freeradius&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2024:0650</guid>
    </item>
    <item>
      <title>EUVD-2026-325750</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325750</link>
      <description>EUVD-2026-325750</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325750</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3596</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3596</link>
      <description>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3596</guid>
    </item>
    <item>
      <title>GHSA-3g8x-wqfp-q876</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3g8x-wqfp-q876</link>
      <description>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3g8x-wqfp-q876</guid>
    </item>
    <item>
      <title>gsd-2024-3596</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3596</link>
      <description>gsd-2024-3596</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3596</guid>
    </item>
    <item>
      <title>ICSA-24-193-05 — Siemens SCALANCE, RUGGEDCOM, SIPLUS, and SINEC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-193-05</link>
      <description>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify responses Access-Reject or Access-Accept using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify responses Access-Reject or Access-Accept using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-193-05</guid>
    </item>
    <item>
      <title>OESA-2024-1878 — freeradius security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1878</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: freeradius, openEuler:20.03-LTS-SP4: freeradius, openEuler:24.03-LTS: freeradius, openEuler:22.03-LTS-SP4: freeradius, openEuler:22.03-LTS-SP1: freeradius&lt;/p&gt;
&lt;p&gt;Remote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.(CVE-2024-3596)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: freeradius, openEuler:20.03-LTS-SP4: freeradius, openEuler:24.03-LTS: freeradius, openEuler:22.03-LTS-SP4: freeradius, openEuler:22.03-LTS-SP1: freeradius&lt;/p&gt;
&lt;p&gt;Remote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.(CVE-2024-3596)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1878</guid>
    </item>
    <item>
      <title>RHSA-2024:10852 — Red Hat Security Advisory: RHOAI 2.16.0 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10852</link>
      <description>&lt;p&gt;freeradius: forgery attack pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON werkzeug: python-werkzeug: Werkzeug possible resource exhaustion when parsing file data in forms&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;freeradius: forgery attack pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON werkzeug: python-werkzeug: Werkzeug possible resource exhaustion when parsing file data in forms&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10852</guid>
    </item>
    <item>
      <title>SEVD-2026-104-02 — Third-Party vulnerability on Modicon Networking Managed Switches</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-104-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product. &#13;
 The Modicon Network Managed Switch product provides connectivity for multiple Ethernet devices, network management, enhanced cyber security and more advanced switching features. &#13;
 Failure to apply the mitigation provided below may risk forgery attacks in RADIUS Protocol, which could result in modification of any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response which could result in the possibility of denial of service and loss of confidentiality, integrity of the devices connected to the switch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product. &#13;
 The Modicon Network Managed Switch product provides connectivity for multiple Ethernet devices, network management, enhanced cyber security and more advanced switching features. &#13;
 Failure to apply the mitigation provided below may risk forgery attacks in RADIUS Protocol, which could result in modification of any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response which could result in the possibility of denial of service and loss of confidentiality, integrity of the devices connected to the switch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-104-02</guid>
    </item>
    <item>
      <title>SSA-364175 — SSA-364175: Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices Before V11.1.4-h1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-364175</link>
      <description>&lt;p&gt;The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH&amp;#39;s use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH&amp;#39;s use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-364175</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2359-1 — Security update for freeradius-server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2359-1</link>
      <description>&lt;p&gt;Security update for freeradius-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for freeradius-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2359-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-3596</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3596</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: krb5, Ubuntu:Pro:14.04:LTS: libpam-radius-auth, Ubuntu:Pro:16.04:LTS: krb5, Ubuntu:Pro:16.04:LTS: freeradius, Ubuntu:16.04:LTS: libpam-radius-auth, Ubuntu:18.04:LTS: freeradius, Ubuntu:Pro:18.04:LTS: krb5, Ubuntu:18.04:LTS: libpam-radius-auth, Ubuntu:20.04:LTS: freeradius, Ubuntu:20.04:LTS: krb5 and 7 more&lt;/p&gt;
&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: krb5, Ubuntu:Pro:14.04:LTS: libpam-radius-auth, Ubuntu:Pro:16.04:LTS: krb5, Ubuntu:Pro:16.04:LTS: freeradius, Ubuntu:16.04:LTS: libpam-radius-auth, Ubuntu:18.04:LTS: freeradius, Ubuntu:Pro:18.04:LTS: krb5, Ubuntu:18.04:LTS: libpam-radius-auth, Ubuntu:20.04:LTS: freeradius, Ubuntu:20.04:LTS: krb5 and 7 more&lt;/p&gt;
&lt;p&gt;RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3596</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1578 — RADIUS: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1578</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im RADIUS Protokoll ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im RADIUS Protokoll ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1578</guid>
    </item>
  </channel>
</rss>
