Freeradius

Vendor:

First CVE: Mar 4, 2002 · Active for 24 years

47
Total CVEs
More Total CVEs than 98% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Freeradius over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2002
24 years ago
Most Recent CVE
Jul 9, 2024
749 days ago

CVE Severity & Scoring

Freeradius47 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network22 (46.8%)
Unknown23 (48.9%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low19 (40.4%)
High5 (10.6%)
Unknown23 (48.9%)
User Interaction
None24 (51.1%)
Unknown23 (48.9%)
Required0 (0.0%)
Privileges Required
Low2 (4.3%)
High0 (0.0%)
None22 (46.8%)
Unknown23 (48.9%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot
Jul 9, 20249.038NONO
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
Apr 22, 20199.835NONO
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly
Jul 17, 20179.833NONO
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly
Jul 17, 20179.832NONO
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauth
May 29, 20179.832NONO
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and ear
Nov 2, 20147.532NONO
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated
Sep 9, 20095.032NOYES
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve bei
Apr 22, 20199.831NONO
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
Jul 17, 20177.526NONO
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-boun
Mar 27, 20178.126NONO

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Freeradius

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.019.83.9%00
3.1.319.83.9%00
3.1.219.83.9%00
3.1.119.83.9%00
3.1.019.83.9%00
3.0.968.33.7%00
3.0.8107.92.8%00
3.0.7107.92.8%00
3.0.6107.92.8%00
3.0.5107.92.8%00
3.0.4107.92.8%00
3.0.3107.92.8%00
3.0.2107.92.8%00
3.0.1458.03.6%00
3.0.1358.03.6%00
3.0.1258.03.6%00
3.0.1158.03.6%00
3.0.1058.03.6%00
3.0.1117.92.9%00
3.0.0117.92.9%00