CVE-2024-3596 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
- 🔗 datatracker.ietf.org/doc/html/rfc2865
- 🔗 datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/
- 🔗 networkradius.com/assets/pdf/radius_and_md5_collisions.pdf
- 🔗 www.blastradius.fail/
- 🔗 www.openwall.com/lists/oss-security/2024/07/09/4
- 🔗 psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014
- 🔗 cert-portal.siemens.com/productcert/html/ssa-794185.html
- 🔗 cert-portal.siemens.com/productcert/html/ssa-723487.html
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-02 | 2026-09-20 |
|---|---|---|
| ≥90 % | 0 | 489 |
| ≥50 % | 0 | 1477 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 0 |
CVE-2024-3596 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against