CVE-2022-41859

In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
freeradiusfreeradius
𝑥
< 3.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeradius
bullseye
no-dsa
bookworm
3.2.1+dfsg-4+deb12u1
fixed
sid
3.2.5+dfsg-3
fixed
trixie
3.2.5+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeradius
kinetic
not-affected
jammy
not-affected
focal
ignored
bionic
ignored
xenial
not-affected
trusty
ignored