7.5

CVE-2015-4680

FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.

Data is provided by the National Vulnerability Database (NVD)
FreeradiusFreeradius Version3.0.0
FreeradiusFreeradius Version3.0.1
FreeradiusFreeradius Version3.0.2
FreeradiusFreeradius Version3.0.3
FreeradiusFreeradius Version3.0.4
FreeradiusFreeradius Version3.0.5
FreeradiusFreeradius Version3.0.6
FreeradiusFreeradius Version3.0.7
FreeradiusFreeradius Version3.0.8
FreeradiusFreeradius Version2.2.0
FreeradiusFreeradius Version2.2.1
FreeradiusFreeradius Version2.2.2
FreeradiusFreeradius Version2.2.3
FreeradiusFreeradius Version2.2.4
FreeradiusFreeradius Version2.2.5
FreeradiusFreeradius Version2.2.6
FreeradiusFreeradius Version2.2.7
SuseLinux Enterprise Server Version12 Updatesp1
SuseLinux Enterprise Server Version12 Updatesp2
SuseLinux Enterprise Server Version12 Updatesp2 HwPlatformraspberry_pi
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.587
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.