New Blast-RADIUS attack bypasses widely-used RADIUS authentication
ID: 494a26c8-412d-5d86-9a7a-97c7cacafe35
STIX ID: report--494a26c8-412d-5d86-9a7a-97c7cacafe35
Feed Name: Bleeping Computer
Threat Score
Blast-RADIUS (CVE-2024-3596) is a critical RADIUS protocol vulnerability that leverages an MD5 chosen-prefix collision in an online man-in-the-middle attack to forge Access-Accept responses and escalate privileges on network and telecom devices; mitigations include RADIUS over TLS (RADSEC), multihop architectures, and isolating RADIUS traffic, while the public PoC has not been released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
