logo

New Blast-RADIUS attack bypasses widely-used RADIUS authentication

ID: 494a26c8-412d-5d86-9a7a-97c7cacafe35

STIX ID: report--494a26c8-412d-5d86-9a7a-97c7cacafe35

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-07-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Blast-RADIUS (CVE-2024-3596) is a critical RADIUS protocol vulnerability that leverages an MD5 chosen-prefix collision in an online man-in-the-middle attack to forge Access-Accept responses and escalate privileges on network and telecom devices; mitigations include RADIUS over TLS (RADSEC), multihop architectures, and isolating RADIUS traffic, while the public PoC has not been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.