RADIUS
RADIUS (Remote Authentication Dial-In User Service) is a protocol, defined in RFC 2865, that network devices such as switches, wireless controllers and VPN gateways use to ask a central server whether a user or device may connect, and with what access.
RADIUS sits underneath most enterprise Wi-Fi and wired 802.1X, VPN sign-in and network device administration, with servers such as Cisco ISE, Microsoft NPS and FreeRADIUS making the decisions and often consulting Active Directory. Each network device shares a secret with the server, and classic RADIUS over UDP protects responses with MD5-based checks; the 2024 Blast-RADIUS attack (CVE-2024-3596) showed those responses could be forged by an attacker in the network path, and the recommended mitigations are requiring the Message-Authenticator attribute and moving to RADIUS over TLS (RadSec). The server itself is tier-zero infrastructure: it decides who gets on the network and holds the secrets every device trusts, which is why the exploited Cisco ISE flaw in September 2026 was an identity incident, not just a patch.
See also: LDAP, Active Directory, ZTNA, federation
Related on Start with Identity
- GlossaryKerberos
A ticket-based network authentication protocol using symmetric cryptography and a trusted third party, the Key Distribution Center. A client authenticates once,
- GlossaryNTLM
A challenge-response authentication protocol used by Windows before Kerberos and still present as a fallback. The client proves knowledge of a password hash wit
- CVEHashiCorp Vault LDAP auth username enumeration
Vault's LDAP auth method returned different errors for unknown and known users. Enumeration is how a lockout or MFA-bypass chain starts. Fixed in 1.14.1 and the
- GlossaryIdentity Resilience
The ability to keep authenticating and authorising legitimate users, and to recover the identity system itself, when the identity provider or directory is degra
- CVELDAPNightmare, domain-controller DoS via crafted LDAP response
A crafted LDAP response crashes the Windows LDAP client and can take a domain controller down. SafeBreach published a PoC in January 2025. High. Patched Decembe
- CVEVault LDAP MFA enforcement bypass
Vault's LDAP auth method could be convinced to skip MFA enforcement. One of the VaultFault MFA-plane bugs. NVD CVSS was not confirmed at the time of the origina