383
VMScore

CVE-2015-8762

Published: 27/03/2017 Updated: 30/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The EAP-PWD module in FreeRADIUS 3.0 up to and including 3.0.8 allows remote malicious users to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

Vulnerable Product Search on Vulmon Subscribe to Product

freeradius freeradius 3.0.1

freeradius freeradius 3.0.8

freeradius freeradius 3.0.3

freeradius freeradius 3.0.4

freeradius freeradius 3.0.5

freeradius freeradius 3.0.6

freeradius freeradius 3.0.0

freeradius freeradius 3.0.2

freeradius freeradius 3.0.7

Vendor Advisories

The EAP-PWD module in FreeRADIUS 30 through 308 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet ...