Showing 2 vulnerabilities on this page for freeradius

Signals CISA KEV Ransomware Nuclei
freeradius vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."

CVSS7.0v3.1EPSS0.345%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

freeradius freeradius Loop with Unreachable Exit Condition ('Infinite Loop')

An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.

CWE-835Jul 17, 2017
CVSS7.5v3.0EPSS2.82%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX