Vulnerabilities > Uninett > Radsecproxy > 1.3.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-28 CVE-2021-32642 Injection vulnerability in multiple products
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports.
network
low complexity
uninett fedoraproject CWE-74
critical
9.4
2012-11-20 CVE-2012-4523 Permissions, Privileges, and Access Controls vulnerability in Uninett Radsecproxy
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.
network
low complexity
uninett CWE-264
6.4