Vulnerabilities > CVE-2024-3596 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in multiple products

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
freeradius
broadcom
sonicwall
CWE-924
critical

Summary

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Vulnerable Configurations

Part Description Count
Application
Freeradius
99
Application
Broadcom
1
OS
Broadcom
1
OS
Sonicwall
1