7.5
CVSSv2

CVE-2004-2163

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote malicious users to bypass authentication by spoofing server replies.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openbsd 3.2

openbsd openbsd 3.4

openbsd openbsd 3.5