logo

RADIUS networking protocol blasted into submission through MD5-based flaw

ID: a0c6177e-32bc-59f0-8499-f1a1cc9f4ab1

STIX ID: report--a0c6177e-32bc-59f0-8499-f1a1cc9f4ab1

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-07-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Blast RADIUS (CVE-2024-3596) is a protocol vulnerability in RADIUS (CVSS 7.5) that enables an attacker who can intercept RADIUS traffic to manipulate Access-Request/Response exchanges and, via MD5 chosen-prefix collision techniques, forge Access-Accept responses to authenticate without valid credentials; exploitation is non-trivial (requires MITM access and rapid cryptographic work), affects deployments using PAP/CHAP/MS-CHAPv2 and other non-EAP methods, and is mitigated by applying vendor patches and moving RADIUS to TLS (RadSec).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.