Wichert Akkerman

2 exploits Active since Dec 2019
CVE-2013-0294 WRITEUP MEDIUM WRITEUP
pyrad < 2.1 - Use of Insufficiently Random Values in RADIUS Authenticator and Password Hash Generation
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
CVSS 5.9
CVE-2013-0342 WRITEUP MEDIUM WRITEUP
pyrad < 2.1 - Predictable Packet ID Spoofing via Sequential ID Generation
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
CVSS 4.3