CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-3596

CVSS 9.0v3.1pub. 2024-07-09upd. 2026-05-12

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

🤖 AI Analysis
How it works

An attacker in a local position (man-in-the-middle on the network between the RADIUS client and server) exploits a chosen-prefix collision attack against the MD5 Response Authenticator signature. The MD5 algorithm used to sign RADIUS responses is cryptographically weak and vulnerable to this type of collision. This allows the attacker to construct a forged response whose MD5 signature will be correctly verified by the client, even though the packet content has been modified — for example, an Access-Reject response can be replaced with Access-Accept.

Impact

An attacker can gain unauthorized access to networks or resources protected by RADIUS by replacing access denial responses with acceptance. Depending on the deployment context, it is possible to take control of network infrastructure and violate data confidentiality and integrity.

Mitigation & patch

Patches available from vendors should be applied according to references. Migration to newer versions of the RADIUS protocol using stronger cryptographic mechanisms is recommended (e.g., RADIUS over TLS — RadSec), in accordance with IETF draft-ietf-radext-deprecating-radius. Additionally, RADIUS traffic should be isolated in dedicated, trusted network segments, limiting the possibility of carrying out a man-in-the-middle attack.

Who is affected

All implementations of the RADIUS protocol compliant with RFC 2865 using MD5 to sign responses, including: FreeRADIUS, Broadcom Brocade SANnav, Broadcom Fabric Operating System, and SonicWall SonicOS. Specific versions are indicated in vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Broadcom Brocade Sannav

    APP
    Broadcom
    all versions
  • Broadcom Fabric Operating System

    OS
    Broadcom
    all versions
  • Freeradius

    APP
    Freeradius
    < 3.0.27
  • Sonicwall Sonicos

    OS
    Sonicwall
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-53704CRITICAL9.8⚠ KEVPL ✓same product

SonicWall SonicOS SSLVPN — pominięcie uwierzytelnienia (Auth Bypass)

CVE-2024-40766CRITICAL9.8⚠ KEVPL ✓same product

Nieprawidłowa kontrola dostępu w SonicWall SonicOS — RCE i crash firewalla

CVE-2020-5135CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w SonicOS umożliwiający DoS i zdalne wykonanie kodu

CVE-2025-40600CRITICAL9.8PL ✓same product

SonicOS SSL VPN: format string umożliwia zakłócenie usługi bez uwierzytelnienia

CVE-2024-22394CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w SonicWall SonicOS SSL-VPN (auth bypass)