logo

RADIUS/UDP vulnerable to improved MD5 collision attack

ID: 255c6f22-2e53-5b7c-a2d1-bf11906a1322

STIX ID: report--255c6f22-2e53-5b7c-a2d1-bf11906a1322

Feed Name: Cloudflare Blog

Threat Score
75/100

Date Published: 2024-07-09

Date Updated: 2026-04-27

Author: Sharon Goldberg

...
...

This report presents the Blast-RADIUS attack: an improved MD5 chosen-prefix collision exploit that enables a MitM with access to RADIUS/UDP traffic to forge Response Authenticators and escalate to administrative access on routers and switches. The authors describe the attack flow (using Proxy-State to inject collision gibberish), performance improvements making collisions practical in minutes, coordinated disclosure (CVE-2024-3596), and mitigations including migrating to RADIUS-over-TLS (RADSEC) or requiring HMAC-based Message-Authenticator attributes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.