CVE-2013-0294

MEDIUM

pyrad < 2.1 - Use of Insufficiently Random Values in RADIUS Authenticator and Password Hash Generation

Title source: llm
STIX 2.1

Description

packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.

References (8)

Core 8
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=911682
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/57984
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2013/02/15/13
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/82133
Mailing List, Third Party Advisory x_refsource_confirm
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116567.html
Mailing List, Third Party Advisory x_refsource_confirm
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115705.html
Mailing List, Third Party Advisory x_refsource_confirm
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115677.html

Scores

CVSS v3 5.9
EPSS 0.0283
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-330
Status published
Products (5)
fedoraproject/fedora 18
fedoraproject/fedora 19
fedoraproject/fedora 20
pypi/pyrad 0 - 2.1PyPI
pyrad_project/pyrad < 2.1
Published Jan 28, 2020
Tracked Since Feb 18, 2026