Vulnerability Name: | CVE-2011-2701 (CCN-68782) | ||||||||
Assigned: | 2011-07-25 | ||||||||
Published: | 2011-07-25 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Jul 25 2011 [DSB-2011-01] Security Advisory FreeRADIUS 2.1.11 Source: MITRE Type: CNA CVE-2011-2701 Source: CCN Type: FreeRADIUS Web site FreeRADIUS: The world's most popular RADIUS Server Source: CCN Type: SA45425 FreeRADIUS OCSP Authentication Bypass Vulnerability Source: SECUNIA Type: Vendor Advisory 45425 Source: SREASON Type: UNKNOWN 8325 Source: SECTRACK Type: UNKNOWN 1025833 Source: MLIST Type: UNKNOWN [oss-security] 20110715 CVE request: vulnerability in FreeRADIUS (OCSP) Source: MLIST Type: UNKNOWN [oss-security] 20110718 Re: CVE request: vulnerability in FreeRADIUS (OCSP) Source: MLIST Type: UNKNOWN [oss-security] 20110720 Re: CVE request: vulnerability in FreeRADIUS (OCSP) Source: CCN Type: OSVDB ID: 74168 FreeRADIUS OCSP Certificate Validation Weakness Access Restriction Bypass Source: BUGTRAQ Type: UNKNOWN 20110725 [DSB-2011-01] Security Advisory FreeRADIUS 2.1.11 Source: BID Type: UNKNOWN 48880 Source: CCN Type: BID-48880 FreeRADIUS Revoked Certificate Authentication Bypass Vulnerability Source: MISC Type: Patch https://bugzilla.redhat.com/show_bug.cgi?id=724815 Source: XF Type: UNKNOWN freeradius-certificate-security-bypass(68782) Source: XF Type: UNKNOWN freeradius-certificate-security-bypass(68782) Source: MISC Type: UNKNOWN https://www.dfn-cert.de/informationen/Sicherheitsbulletins/dsb-2011-01.html | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |