RADIUS Vulnerability
New attack against the RADIUS authentication protocol:
The Blast-RADIUS attack allows a man-in-the-middle attacker between the RADIUS client and server to forge a valid protocol accept message in response to a failed authentication request. This forgery could give the attacker access to network devices and services without the attacker guessing or brute forcing passwords or shared secrets. The attacker does not learn user credentials.
This is one of those vulnerabilities that comes with a cool name, its own website, and a logo.
Subscribe to comments on this entry
ngô ############ long • July 10, 2024 10:10 PM
on a scale from 1-10, how screwed up are we? i mean RADIUS is an incredibly common protocol used for securing info