FreeRADIUS is a widely embedded open-source authentication and access-control server that sits in the critical path of network access decisions across enterprise networks, ISPs, and service providers, despite its narrow product line. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs in the core FreeRADIUS server and its PAM integration through weakness classes including memory buffer violations, improper authentication logic, and out-of-bounds reads and writes that reflect the parsing and state-management demands of the RADIUS protocol implementation. The structural importance of RADIUS to network access infrastructure means that flaws in this vendor can affect authentication and authorization mechanisms across an entire organization's edge and internal systems. Defenders should treat FreeRADIUS updates as high-priority for any deployment that handles network access control, and should inventory dependent systems that rely on this authentication service; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeradius over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3596CRITICAL RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot | Jul 9, 2024 | 9.0 | 38 | NO | NO |
CVE-2019-11234CRITICAL FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. | Apr 22, 2019 | 9.8 | 35 | NO | NO |
CVE-2017-10979CRITICAL An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly | Jul 17, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-10984CRITICAL An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly | Jul 17, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-9148CRITICAL The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauth | May 29, 2017 | 9.8 | 32 | NO | NO |
CVE-2014-2015HIGH Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and ear | Nov 2, 2014 | 7.5 | 32 | NO | NO |
CVE-2009-3111MEDIUM The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated | Sep 9, 2009 | 5.0 | 32 | NO | YES |
CVE-2019-11235CRITICAL FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve bei | Apr 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-10986HIGH An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service. | Jul 17, 2017 | 7.5 | 26 | NO | NO |
CVE-2015-8763HIGH The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-boun | Mar 27, 2017 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeradius.
Media articles that mention a CVE ID that affects a product developed by Freeradius — matched by CVE ID, not by vendor name.