Threat Advisory

Critical RADIUS Protocol Vulnerability Exposes Networks to Authentication Risks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability tracked as CVE-2024-3596 affects RADIUS protocol implementations, impacting all standards-compliant RADIUS clients and servers. Exploiting a fundamental design flaw, the vulnerability enables attackers to forge authentication responses in scenarios lacking Message-Authenticator attribute enforcement, potentially leading to unauthorized administrative access. Organizations relying on vulnerable authentication methods like PAP, CHAP, and MS-CHAPv2, or transmitting RADIUS/UDP traffic over the internet without TLS or IPSec protection, are at high risk. It involves updating RADIUS servers and networking equipment to versions that enforce Message-Authenticator attribute usage and implementing secure transport protocols like TLS or IPSec.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability tracked as CVE-2024-3596 affects RADIUS protocol implementations, impacting all standards-compliant RADIUS clients and servers. Exploiting a fundamental design flaw, the vulnerability enables attackers to forge authentication responses in scenarios lacking Message-Authenticator attribute enforcement, potentially leading to unauthorized administrative access. Organizations relying on vulnerable authentication methods like PAP, CHAP, and MS-CHAPv2, or transmitting RADIUS/UDP traffic over the internet without TLS or IPSec protection, are at high risk. It involves updating RADIUS servers and networking equipment to versions that enforce Message-Authenticator attribute usage and implementing secure transport protocols like TLS or IPSec.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update RADIUS Protocol to version 3.2.5.

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/07/radius-protocol-vulnerability-exposes.html

[/emaillocker]
crossmenu