Website Security & Threat Management
RADIUS/UDP vulnerable to improved MD5 collision attack

RADIUS/UDP vulnerable to improved MD5 collision attack

7/9/2024 · Sharon Goldberg, Miro Haller, Nadia Heninger, Michael Milano, Dan Shumow, Marc Stevens, Adam Suhl

What this post added

This post details a new 'Blast-RADIUS' attack that exploits MD5 collision vulnerabilities in RADIUS/UDP authentication modes (PAP, CHAP, MS-CHAP). The attack allows a Man-in-the-Middle to gain unauthorized administrative access to network devices by forging RADIUS responses. It highlights the protocol's reliance on outdated cryptography and proposes mitigations including using RADIUS over TLS/DTLS or disabling vulnerable authentication modes.

Read the original post ↗