Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freeradius

First CVE: Mar 4, 2002Active for: 24 yearsTotal CVEs: 49
51.9
VTI Score
TOP TARGET

FreeRADIUS is a widely embedded open-source authentication and access-control server that sits in the critical path of network access decisions across enterprise networks, ISPs, and service providers, despite its narrow product line. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs in the core FreeRADIUS server and its PAM integration through weakness classes including memory buffer violations, improper authentication logic, and out-of-bounds reads and writes that reflect the parsing and state-management demands of the RADIUS protocol implementation. The structural importance of RADIUS to network access infrastructure means that flaws in this vendor can affect authentication and authorization mechanisms across an entire organization's edge and internal systems. Defenders should treat FreeRADIUS updates as high-priority for any deployment that handles network access control, and should inventory dependent systems that rely on this authentication service; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
49
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freeradius over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2002
24 years ago
Most Recent CVE
Jul 9, 2024
745 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-3596CRITICAL
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot
Jul 9, 20249.038NONO
CVE-2019-11234CRITICAL
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
Apr 22, 20199.835NONO
CVE-2017-10979CRITICAL
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly
Jul 17, 20179.833NONO
CVE-2017-10984CRITICAL
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly
Jul 17, 20179.832NONO
CVE-2017-9148CRITICAL
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauth
May 29, 20179.832NONO
CVE-2014-2015HIGH
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and ear
Nov 2, 20147.532NONO
CVE-2009-3111MEDIUM
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated
Sep 9, 20095.032NOYES
CVE-2019-11235CRITICAL
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve bei
Apr 22, 20199.831NONO
CVE-2017-10986HIGH
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
Jul 17, 20177.526NONO
CVE-2015-8763HIGH
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-boun
Mar 27, 20178.126NONO
View all 49 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products49 CVEs
37%
51%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.0%)
Network23 (46.9%)
Unknown24 (49.0%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low20 (40.8%)
High5 (10.2%)
Unknown24 (49.0%)
User Interaction
None25 (51.0%)
Unknown24 (49.0%)
Required0 (0.0%)
Privileges Required
Low2 (4.1%)
High0 (0.0%)
None23 (46.9%)
Unknown24 (49.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freeradius.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freeradius — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freeradius's Products

View all 3 CNAs →

Top CWEs