CVE-2017-9148

EUVD-2017-18086
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
freeradiusfreeradius
2.1.1
freeradiusfreeradius
2.1.2
freeradiusfreeradius
2.1.3
freeradiusfreeradius
2.1.4
freeradiusfreeradius
2.1.6
freeradiusfreeradius
2.1.7
freeradiusfreeradius
3.0.0
freeradiusfreeradius
3.0.1
freeradiusfreeradius
3.0.2
freeradiusfreeradius
3.0.3
freeradiusfreeradius
3.0.4
freeradiusfreeradius
3.0.5
freeradiusfreeradius
3.0.6
freeradiusfreeradius
3.0.7
freeradiusfreeradius
3.0.8
freeradiusfreeradius
3.0.9
freeradiusfreeradius
3.1.0
freeradiusfreeradius
3.1.1
freeradiusfreeradius
3.1.2
freeradiusfreeradius
3.1.3
freeradiusfreeradius
4.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeradius
bookworm
3.2.1+dfsg-4+deb12u1
fixed
bullseye
3.0.21+dfsg-2.2+deb11u1
fixed
jessie
not-affected
sid
3.2.5+dfsg-3
fixed
trixie
3.2.5+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeradius
trusty
dne
xenial
not-affected
yakkety
not-affected
zesty
Fixed 3.0.12+dfsg-4ubuntu1.1
released