4.3
CVSSv3

CVE-2013-0342

Published: 09/12/2019 Updated: 11/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The CreateID function in packet.py in pyrad prior to 2.1 uses sequential packet IDs, which makes it easier for remote malicious users to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pyrad project pyrad

Vendor Advisories

Debian Bug report logs - #701151 pyrad: CVE-2013-0342: CreateID() creates serialized packet IDs for RADIUS Package: pyrad; Maintainer for pyrad is Jeremy Lainé <jeremylaine@m4xorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Feb 2013 06:21:01 UTC Severity: important Tags: security Found i ...