Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10697
HistoryJan 15, 2019 - 8:50 a.m.

Authentication Bypass

2019-01-1508:50:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

70.9%

freeradius is vulnerable to authentication bypass attacks. The vulnerability exists due to the failure to check on password expiration in /etc/shadow in modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is used for user authentication. This allows an expired password to be used for authentication.