CVE-2017-9148
Published May 29, 2017
Last updated 7 years ago
Overview
- Description
- The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5CAEB64-0676-4C18-8255-DACDA612188E" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17F7A434-49DC-4005-9161-F2B49559621F" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A54D59A-B832-4EE3-A8D6-A85EC17C268A" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D494932F-F639-44BE-B15C-7F07A67B0502" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2D45784-C53B-4A11-B1B3-BC68B514002D" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E969979B-2852-453D-AF48-A462448D4C62" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "388D7673-6BA7-4113-86E1-00F9A60C8796" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B5B5D50-C251-4569-9D2C-49FB64702646" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A693BD6B-BCFF-461B-B71D-4E6F7A614979" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E1D867F-7147-4C97-927B-C10404CC2985" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BD8346B-8A41-43DF-9AFE-06E3546B6AC9" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C30EB50-6BCD-44E4-906A-618ACCF627DC" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8C129A8-59C9-4780-8454-4EB112DF0B40" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13C228DD-0EB3-4348-8D7A-D17A59E92013" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2400422C-8E52-4946-BE83-AA7167F0F703" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1841E98-2B17-4DFC-B03F-4E4537D8A6A7" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78140938-FD3B-442E-B906-7705CDFF853D" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "354381FC-52F3-4377-8DE0-75FC0D2D7FD2" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D829A428-71E8-4EB4-A8D7-BD5B673AA51F" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:3.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F800631-5190-410F-B11D-02CF956D5B93" }, { "criteria": "cpe:2.3:a:freeradius:freeradius:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8AA8D994-16CB-44F0-95FE-7AFECB56C949" } ], "operator": "OR" } ] } ]