CVE-2004-2163: High severity OpenBSD OpenBSD vulnerability
Published Dec 31, 2004
·Updated
loginradius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.
Affected Software
3 affected components
OpenBSD OpenBSD=3.2
OpenBSD OpenBSD=3.5
OpenBSD OpenBSD=3.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2163?
CVE-2004-2163 is considered a high severity vulnerability due to the potential for remote attackers to bypass authentication.
2
How do I fix CVE-2004-2163?
To fix CVE-2004-2163, you should upgrade to a patched version of OpenBSD that addresses this vulnerability.
3
What systems are affected by CVE-2004-2163?
CVE-2004-2163 affects OpenBSD versions 3.2, 3.4, and 3.5.
4
What is the cause of CVE-2004-2163?
CVE-2004-2163 occurs because login_radius does not verify the shared secret in response packets from the RADIUS server.
5
Can CVE-2004-2163 be exploited remotely?
Yes, CVE-2004-2163 can be exploited remotely by attackers to spoof RADIUS server replies and bypass authentication.