RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
An attacker in a local position (man-in-the-middle on the network between the RADIUS client and server) exploits a chosen-prefix collision attack against the MD5 Response Authenticator signature. The MD5 algorithm used to sign RADIUS responses is cryptographically weak and vulnerable to this type of collision. This allows the attacker to construct a forged response whose MD5 signature will be correctly verified by the client, even though the packet content has been modified — for example, an Access-Reject response can be replaced with Access-Accept.
An attacker can gain unauthorized access to networks or resources protected by RADIUS by replacing access denial responses with acceptance. Depending on the deployment context, it is possible to take control of network infrastructure and violate data confidentiality and integrity.
Patches available from vendors should be applied according to references. Migration to newer versions of the RADIUS protocol using stronger cryptographic mechanisms is recommended (e.g., RADIUS over TLS — RadSec), in accordance with IETF draft-ietf-radext-deprecating-radius. Additionally, RADIUS traffic should be isolated in dedicated, trusted network segments, limiting the possibility of carrying out a man-in-the-middle attack.
All implementations of the RADIUS protocol compliant with RFC 2865 using MD5 to sign responses, including: FreeRADIUS, Broadcom Brocade SANnav, Broadcom Fabric Operating System, and SonicWall SonicOS. Specific versions are indicated in vendor references.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HBroadcom Brocade Sannav
APPBroadcomall versionsBroadcom Fabric Operating System
OSBroadcomall versionsFreeradius
APPFreeradius< 3.0.27Sonicwall Sonicos
OSSonicwallall versions
Related vulnerabilities
SonicWall SonicOS SSLVPN — pominięcie uwierzytelnienia (Auth Bypass)
Nieprawidłowa kontrola dostępu w SonicWall SonicOS — RCE i crash firewalla
Buffer overflow w SonicOS umożliwiający DoS i zdalne wykonanie kodu
SonicOS SSL VPN: format string umożliwia zakłócenie usługi bez uwierzytelnienia
Pominięcie uwierzytelnienia w SonicWall SonicOS SSL-VPN (auth bypass)