Improper Certificate Validation in FreeRADIUS - CVE-2015-4680
Published: April 5, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32360
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-4680
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
Affected software
FreeRADIUS
freeradius (Alpine package)
SUSE Linux
freeradius (Alpine package)
SUSE Linux
How to mitigate CVE-2015-4680
Install update from vendor's website.
FreeRADIUS - update to 2.2.8
freeradius (Alpine package) - update to 2.2.9-r0
freeradius (Alpine package) - update to 2.2.9-r0
External References
- http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00010.html
- http://packetstormsecurity.com/files/132415/FreeRADIUS-Insufficient-CRL-Application.html
- http://www.ocert.org/advisories/ocert-2015-008.html
- http://www.securityfocus.com/archive/1/535810/100/0/threaded
- http://www.securityfocus.com/bid/75327
- http://www.securitytracker.com/id/1032690
- https://bugzilla.redhat.com/show_bug.cgi?id=1234975