Protocol · 1 briefs
RADIUS identity CVEs
Blast-RADIUS is a protocol-level Access-Accept forge. MFA that sits behind RADIUS without Message-Authenticator is optional.
How this protocol fails
RADIUS still fronts VPN, Wi-Fi, and a surprising amount of MFA. A chosen-prefix MD5 collision on the Response Authenticator lets an on-path attacker turn Reject into Accept. Vendor patching ran into 2026. This is not a single-product bug. It is every NAS that still speaks RFC 2865 without Message-Authenticator or RadSec.
What security people should do
- Require Message-Authenticator on every client and server. Reject packets that omit it.
- Move to RadSec (RADIUS over TLS) where the NAS supports it.
- Stop sending PAP/CHAP across a network you do not trust.
- Inventory MFA products that still front RADIUS. A phishing-resistant factor behind a forgeable Accept is not phishing-resistant.
CVEs in this category
1
RADIUS
0
On CISA KEV
0
Actively exploited
1
Showing
Severity
Year
Status
Showing 1 of 1
Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.