5

CVE-2001-1377

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Data is provided by the National Vulnerability Database (NVD)
FreeradiusFreeradius Version0.2
FreeradiusFreeradius Version0.3
GnuRadius Version0.92.1
GnuRadius Version0.93
GnuRadius Version0.94
GnuRadius Version0.95
IcradiusIcradius Version0.14
IcradiusIcradius Version0.15
IcradiusIcradius Version0.16
IcradiusIcradius Version0.17
IcradiusIcradius Version0.17b
IcradiusIcradius Version0.18
IcradiusIcradius Version0.18.1
LivingstonRadius Version2.0
LivingstonRadius Version2.0.1
LivingstonRadius Version2.1
LucentRadius Version2.0
LucentRadius Version2.0.1
LucentRadius Version2.1
OpenradiusOpenradius Version0.8
OpenradiusOpenradius Version0.9
OpenradiusOpenradius Version0.9.1
OpenradiusOpenradius Version0.9.2
OpenradiusOpenradius Version0.9.3
RadiusclientRadiusclient Version0.3.1
XtradiusXtradius Version1.1_pre1
XtradiusXtradius Version1.1_pre2
Yard RadiusYard Radius Version1.0.17
Yard RadiusYard Radius Version1.0.18
Yard RadiusYard Radius Version1.0.19
Yard RadiusYard Radius Version1.0_pre13
Yard RadiusYard Radius Version1.0_pre14
Yard RadiusYard Radius Version1.0_pre15
Yard Radius ProjectYard Radius Version1.0.16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.28% 0.924
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P