CVE-2019-11235: Critical severity FreeRADIUS freeradius vulnerability
A vulnerability was found in FreeRadius. An invalid curve attack allows an attacker to authenticate as any user (without knowing the password). The problem is that on the reception of an EAP-PWD Commit frame, FreeRADIUS doesn't verify whether the received elliptic curve point is valid.
Other sources
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11235?
CVE-2019-11235 has a high severity level due to its potential to allow an attacker to authenticate as any user.
How do I fix CVE-2019-11235?
To fix CVE-2019-11235, upgrade FreeRADIUS to version 3.0.21 or later.
Which FreeRADIUS versions are affected by CVE-2019-11235?
CVE-2019-11235 affects FreeRADIUS versions prior to 3.0.21.
What type of attack does CVE-2019-11235 involve?
CVE-2019-11235 involves an invalid curve attack that exploits EAP-PWD Commit frame handling.
Is CVE-2019-11235 exploitable remotely?
Yes, CVE-2019-11235 is exploitable remotely without requiring physical access to the server.