RADIUS Protocol Vulnerability Exposes Networks to MitM Attacks
ID: d276f93d-e0f5-52c8-b1df-f47e2c353472
STIX ID: report--d276f93d-e0f5-52c8-b1df-f47e2c353472
Feed Name: The Hacker News
Researchers disclosed "BlastRADIUS" (CVE-2024-3596), a critical protocol design flaw in RADIUS that leverages MD5 collision attacks to allow an attacker with access to RADIUS/UDP traffic to forge authentication responses, potentially granting unauthorized administrative access and arbitrary authorizations; the issue affects standards-compliant RADIUS implementations (notably PAP, CHAP, MS-CHAPv2) but can be mitigated by TLS/IPSec, enforcing Message-Authenticator, or using 802.1X, and there is no evidence of active exploitation at the time of the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
