Vulnerability CVE-2024-3596


Published: 2024-07-09

Description:
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

 References:
https://datatracker.ietf.org/doc/html/rfc2865
https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/
https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf
https://www.blastradius.fail/

Copyright 2026, cxsecurity.com

 

Back to Top