Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-13456

23
FAUCET Score

CVE-2019-13456 describes an information leakage vulnerability in FreeRADIUS versions 3.0 through 3.0.19, affecting products like Linux, openSUSE, and Red Hat. This flaw, similar to the "Dragonblood" attack, causes approximately 1 in 2048 EAP-pwd handshakes to fail due to an issue in locating the password element. With a CVSS score of 6.5 (Medium), it allows an unauthenticated attacker on the adjacent network to recover user passwords due to the disclosed information. There is no known active exploitation, publicly available exploit code in Metasploit or ExploitDB, and it has received limited community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, <= 3.0.19CPE matchmatch criteria
cpe:2.3:a:freeradius:freeradius:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.63%
Probability of exploitation in next 30 days
EPSS Percentile
73.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0163 is in the 95th percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: freeradius-0:3.0.13-15.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: freeradius:3.0-8020020191122172113.31e953cd
View patch

Vendor Advisories (1)

redhatCVE-2019-13456Moderate

freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations

Aug 3, 2019

References

lists.opensuse.org / opensuse-security-announce/2020-04/msg00039.html
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
ExploitIssue TrackingPatchThird Party Advisory
freeradius.org / security
Vendor Advisory
github.com / FreeRADIUS/freeradius-server/commit/3ea2a5a026e73d81cd9a3e9bbd4300c433004bfa
PatchThird Party Advisory
wpa3.mathyvanhoef.com
ExploitThird Party Advisory