CVE Vulnerabilities

CVE-2015-4680

Improper Certificate Validation

Published: Apr 05, 2017 | Modified: Oct 09, 2018
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Freeradius Freeradius 3.0.0 (including) 3.0.0 (including)
Freeradius Freeradius 3.0.1 (including) 3.0.1 (including)
Freeradius Freeradius 3.0.2 (including) 3.0.2 (including)
Freeradius Freeradius 3.0.3 (including) 3.0.3 (including)
Freeradius Freeradius 3.0.4 (including) 3.0.4 (including)
Freeradius Freeradius 3.0.5 (including) 3.0.5 (including)
Freeradius Freeradius 3.0.6 (including) 3.0.6 (including)
Freeradius Freeradius 3.0.7 (including) 3.0.7 (including)
Freeradius Freeradius 3.0.8 (including) 3.0.8 (including)
Freeradius Ubuntu precise *
Freeradius Ubuntu trusty *
Freeradius Ubuntu upstream *
Freeradius Ubuntu utopic *
Freeradius Ubuntu vivid *
Freeradius Ubuntu wily *

Potential Mitigations

References