CVE-2001-1377
5 documents5 sources
Severity
5.0MEDIUM
EPSS
13.3%
top 5.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4
Latest updateMay 3
Description
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages11 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-365r-qwgj-mv9r: Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a↗2022-05-03
CVEList▶
CVE-2001-1377: Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a↗2002-06-11