CVE-2013-0294
published 2020-01-28CVE-2013-0294: packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.83%
85.0th percentile
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pyrad | < pyrad 2.0-2 (bookworm) | pyrad 2.0-2 (bookworm) |
| debian | pyrad | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| pyrad | pyrad | — | — |
| pyrad | pyrad | >= 0 < 2.0-2 | 2.0-2 |
| pyrad | pyrad | >= 0 < 2.0-2 | 2.0-2 |
| pyrad | pyrad | >= 0 < 2.0-2 | 2.0-2 |
| pyrad | pyrad | >= 0 < 2.0-2 | 2.0-2 |
| pyrad | pyrad | >= 0 < 2.1 | 2.1 |
| pyrad_project | pyrad | < 2.1 | 2.1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
pyrad is vulnerable to the use of Insufficiently Random Values
ghsa·2022-05-05
CVE-2013-0294 [HIGH] CWE-330 pyrad is vulnerable to the use of Insufficiently Random Values
pyrad is vulnerable to the use of Insufficiently Random Values
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
OSV
pyrad uses sequential packet IDs
osv·2022-05-05·CVSS 5.9
CVE-2013-0342 [MEDIUM] pyrad uses sequential packet IDs
pyrad uses sequential packet IDs
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
GHSA
pyrad uses sequential packet IDs
ghsa·2022-05-05·CVSS 5.9
CVE-2013-0342 [MEDIUM] CWE-20 pyrad uses sequential packet IDs
pyrad uses sequential packet IDs
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
OSV
pyrad is vulnerable to the use of Insufficiently Random Values
osv·2022-05-05
CVE-2013-0294 [HIGH] pyrad is vulnerable to the use of Insufficiently Random Values
pyrad is vulnerable to the use of Insufficiently Random Values
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
OSV
CVE-2013-0294: packet
osv·2020-01-28·CVSS 5.9
CVE-2013-0294 [MEDIUM] CVE-2013-0294: packet
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
OSV
CVE-2013-0342: The CreateID function in packet
osv·2019-12-09·CVSS 5.9
CVE-2013-0342 [MEDIUM] CVE-2013-0342: The CreateID function in packet
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
Debian
CVE-2013-0342: pyrad - The CreateID function in packet.py in pyrad before 2.1 uses sequential packet ID...
vendor_debian·2013·CVSS 5.9
CVE-2013-0342 [MEDIUM] CVE-2013-0342: pyrad - The CreateID function in packet.py in pyrad before 2.1 uses sequential packet ID...
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2013-0294: pyrad - packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authen...
vendor_debian·2013·CVSS 5.9
CVE-2013-0294 [MEDIUM] CVE-2013-0294: pyrad - packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authen...
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
Scope: local
bookworm: resolved (fixed in 2.0-2)
bullseye: resolved (fixed in 2.0-2)
forky: resolved (fixed in 2.0-2)
sid: resolved (fixed in 2.0-2)
trixie: resolved (fixed in 2.0-2)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115677.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/115705.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116567.htmlhttp://www.openwall.com/lists/oss-security/2013/02/15/13http://www.securityfocus.com/bid/57984https://bugzilla.redhat.com/show_bug.cgi?id=911682https://exchange.xforce.ibmcloud.com/vulnerabilities/82133https://github.com/wichert/pyrad/commit/38f74b36814ca5b1a27d9898141126af4953bee5http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115677.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/115705.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116567.htmlhttp://www.openwall.com/lists/oss-security/2013/02/15/13http://www.securityfocus.com/bid/57984https://bugzilla.redhat.com/show_bug.cgi?id=911682https://exchange.xforce.ibmcloud.com/vulnerabilities/82133https://github.com/wichert/pyrad/commit/38f74b36814ca5b1a27d9898141126af4953bee5
2020-01-28
Published