VDB

ALPINE-CVE-2024-3596

ALPINE-CVE-2024-3596 PUBLISHED CVSS 9 CRITICAL

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Risk Scores

CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.19freeradius0, 2.2.5-r3, 2.2.6-r0
Alpine:v3.18freeradius2.1.10-r1, 2.1.10-r10, 2.1.10-r11
Alpine:v3.20freeradius2.1.10-r1, 0, 3.0.9-r3
Alpine:v3.23freeradius3.0.26-r8, 3.0.26-r9, 3.0.8-r1
Alpine:v3.21freeradius0, 0, 2.1.10-r0
Alpine:v3.22freeradius2.1.10-r0, 0, 3.0.26-r8
Alpine:v3.24freeradius0

Timeline

  • Jul 9, 2024 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jun 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›