Live data from Hacker News

Radius/UDP Considered Harmful

blastradius.fail

1–2 of 2 posts

Re: Radius/UDP Considered Harmful

#2
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3596

Nothing on oss-security list yet, but it'll appear here: https://www.openwall.com/lists/oss-security/2024/07/09/

Essential reading is this FAQ from DeKok, FreeRADIUS maintainer who revised the RADIUS UDP approach to mitigate: https://www.inkbridgenetworks.com/blastradius/faq