Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r267-cj3p-f63m

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.

The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.

EPSS

Процентиль: 53%
0.00299
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 13 лет назад

The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.

EPSS

Процентиль: 53%
0.00299
Низкий

Дефекты

CWE-287