NA

CVE-2022-41859

Published: 17/01/2023 Updated: 24/01/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an malicious user to substantially reduce the size of an offline dictionary attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeradius freeradius

Vendor Advisories

Synopsis Moderate: freeradius security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for freeradius is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this upd ...
The EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack (CVE-2022-41859) When an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries This lookup will fail, but t ...