Start with Identity
Protocol · 1 briefs

RADIUS identity CVEs

Blast-RADIUS is a protocol-level Access-Accept forge. MFA that sits behind RADIUS without Message-Authenticator is optional.

How this protocol fails

RADIUS still fronts VPN, Wi-Fi, and a surprising amount of MFA. A chosen-prefix MD5 collision on the Response Authenticator lets an on-path attacker turn Reject into Accept. Vendor patching ran into 2026. This is not a single-product bug. It is every NAS that still speaks RFC 2865 without Message-Authenticator or RadSec.

What security people should do

  • Require Message-Authenticator on every client and server. Reject packets that omit it.
  • Move to RadSec (RADIUS over TLS) where the NAS supports it.
  • Stop sending PAP/CHAP across a network you do not trust.
  • Inventory MFA products that still front RADIUS. A phishing-resistant factor behind a forgeable Accept is not phishing-resistant.

CVEs in this category

1
RADIUS
0
On CISA KEV
0
Actively exploited
1
Showing
Severity
Year
Status

Showing 1 of 1

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.