← Vulnerability feed

Vulnerability record · CVE-2024-3596 · published 9 July 2024

CVE-2024-3596: Freeradius vulnerability

Freeradius · Freeradius

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

9.0 CVSS 3.1 Critical EPSS 15% · top 3.4% CWE-354 · CWE-354CWE-924 · CWE-924
9.0CVSS 3.1 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
21References
17 Jun 2026Last modified by NVD

Description

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2024/07/09/4 Mailing List
https://cert-portal.siemens.com/productcert/html/ssa-723487.html
https://cert-portal.siemens.com/productcert/html/ssa-794185.html
https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/ Technical Description
https://datatracker.ietf.org/doc/html/rfc2865 Technical Description
https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014 Third Party Advisory
https://www.blastradius.fail/ Technical Description
http://www.openwall.com/lists/oss-security/2024/07/09/4 Mailing List
https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/ Technical Description
https://datatracker.ietf.org/doc/html/rfc2865 Technical Description
https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014 Third Party Advisory
https://security.netapp.com/advisory/ntap-20240822-0001/ Third Party Advisory
https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol Third Party Advisory
https://www.blastradius.fail/ Technical Description
https://www.kb.cert.org/vuls/id/456537
https://cert-portal.siemens.com/productcert/html/ssa-364175.html
https://cert-portal.siemens.com/productcert/html/ssa-723487.html
https://cert-portal.siemens.com/productcert/html/ssa-770770.html
https://cert-portal.siemens.com/productcert/html/ssa-794185.html

Track CVE-2024-3596 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-53704SonicWall SonicOS SSLVPN authentication bypassSonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a C…KEVEPSS 95%analysed9.8CVE-2024-40766SonicWall SonicOS improper access control in management accessSonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash …KEVEPSS 18%analysed9.8CVE-2020-5135SonicWall SonicOS buffer overflow in firewall request handlingSonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.…KEVEPSS 27%analysed8.6CVE-2025-1976Brocade Fabric OS admin-to-root code injectionBrocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root p…KEVEPSS 0.69%analysed9.8CVE-2025-40600Sonicwall sonicos vulnerabilityUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…EPSS 0.91%9.8CVE-2024-4173Broadcom brocade sannav information exposure vulnerabilityA vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various at…EPSS 0.59%9.8CVE-2024-29966Broadcom brocade sannav hard-coded credentials vulnerabilityBrocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vu…EPSS 0.65%9.8CVE-2023-3454Broadcom fabric operating system os command injection vulnerabilityRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-3596), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.