Hacker News new | ask | show | jobs
Radius/UDP Considered Harmful (blastradius.fail)
13 points by shaananc 704 days ago
1 comments

CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3596

Nothing on oss-security list yet, but it'll appear here: https://www.openwall.com/lists/oss-security/2024/07/09/

Essential reading is this FAQ from DeKok, FreeRADIUS maintainer who revised the RADIUS UDP approach to mitigate: https://www.inkbridgenetworks.com/blastradius/faq