Freeradius
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Freeradius product.
RSS Feeds for Freeradius security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Freeradius products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Freeradius Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Freeradius. Freeradius did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 9.00 |
| 2023 | 3 | 7.17 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 2 | 0.00 |
| 2019 | 3 | 8.87 |
It may take a day or so for new Freeradius vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Freeradius Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2024-3596 | Jul 09, 2024 |
RADIUS MD5 Response Authenticator Forgery via Chosen-Prefix CollisionRADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. |
|
| CVE-2022-41861 | Jan 17, 2023 |
FreeRADIUS Malformed Binary Attribute Crash CVE-2022-41861A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. |
|
| CVE-2022-41860 | Jan 17, 2023 |
FreeRADIUS NULL Deref Crash via Unknown EAP-SIM OptionIn freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash. |
|
| CVE-2022-41859 | Jan 17, 2023 |
FreeRADIUS EAP-PWD compute_password_element info leak (CVE-2022-41859)In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. |
|
| CVE-2019-17185 | Mar 21, 2020 |
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakesIn FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack. |
|
| CVE-2015-9542 | Feb 24, 2020 |
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input passwordadd_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors. |
|
| CVE-2019-10143 | May 24, 2019 |
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotateIt was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue." |
|
| CVE-2019-11234 | Apr 22, 2019 |
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofingFreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
|
| CVE-2019-11235 | Apr 22, 2019 |
FreeRADIUS before 3.0.19 mishandles the "each participant verifiesFreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499. |
|
| CVE-2010-3696 | Oct 07, 2010 |
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packetThe fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information. |
|