CVE-2024-3596

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Acce…

criticalEPSS 15 %

Beschreibung

Das RADIUS-Protokoll gemäß RFC 2865 ist anfällig für Fälschungsangriffe durch einen lokalen Angreifer, der eine gültige Antwort (Access-Accept, Access-Reject oder Access-Challenge) in jede andere Antwort umwandeln kann, indem er einen gewählten Präfix-Kollision-Angriff gegen die MD5-Authentifizierungs-Signatur des Responses verwendet.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.0
Quelle: nvd-v3
96.5 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
14.9 %
Erhöht — Modell schätzt 10-50 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2024-07-09 12:02 UTC

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Oracle

    Communications12.11

  • Oracle

    Communications14

  • Oracle

    Communications15

  • Oracle

    Communications15.0.0.0.0

  • Oracle

    Communications23.4.0

  • Oracle

    Communications23.4.4

  • Oracle

    Communications24.1.0

  • Oracle

    Communications24.1.1

  • Oracle

    Communications24.2.0

  • Oracle

    Communications24.2.1

  • Oracle

    Communications24.2.3

  • Oracle

    Communications24.3.0

  • Oracle

    Communications4.1.0

  • Oracle

    Communications4.2.0

  • Oracle

    Communications47.0.0.0.0

  • Oracle

    Communications5.1

  • Oracle

    Communications5.2

  • Oracle

    Communications8

  • Oracle

    Communications8.1

  • Oracle

    Communications8.2.3.0.0

  • Oracle

    Communications8.6.0.4.0

  • Oracle

    Communications9

  • Oracle

    Communications9.0.0.0.0

  • Oracle

    Communications9.2.0

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2024-3596