Cybersecurity researchers have discovered a vulnerability in the RADIUS protocol, which they have dubbed BlastRADIUS. This vulnerability could be used to carry out Mallory-in-the-middle (MitM) attacks and bypass checks, under certain circumstances.

“The RADIUS protocol allows certain messages to bypass integrity checks or authentication checks,” said InkBridge Networks CEO Alan DeKok, who is the creator of the FreeRADIUS Project.
RADIUS, short for Remote Authentication Dial-In User Service, is a client/server protocol that provides centralized authentication, authorization, and accounting (AAA) management for users connecting to and using a network service.
See also: HCL Domino: Vulnerability allows information disclosure
RADIUS security is based on a hash derived from the MD5 algorithm, which appears to be less secure. Access-Request packets can be subjected to what is called a “chosen prefix attack,” which makes it possible to modify the response packet so that it passes all integrity checks for the original response.
However, for the attack to succeed, the attacker must be able to modify RADIUS packets in transit between the RADIUS client and server. This means that organizations that send packets over the Internet are at risk from this vulnerability.
The BlastRADIUS vulnerability is the result of a fundamental design flaw and is said to affect all standards-compliant RADIUS clients and servers. This means that Internet service providers (ISPs) and organizations that use the RADIUS protocol should upgrade to the latest version.
See also: APT40: Exploits vulnerabilities within hours of their announcement
“authentication methods PAP, CHAP, and MS-CHAPv2 are the most vulnerable,” DeKok said. “ISPs should upgrade their RADIUS servers and network equipment.”
“Anyone using MAC address authentication or RADIUS for administrator logins on switches is vulnerable. Using TLS or IPSec prevents the attack and 802.1X (EAP) is not vulnerable“.
For enterprises, the attacker would already need to have access to the virtual local area network (VLAN). ISPs may be vulnerable if they send RADIUS traffic through intermediate networks, such as third-party outsourcers.

The vulnerability particularly affects networks that send RADIUS/UDP traffic over the Internet.
See also: Microsoft SmartScreen vulnerability used to distribute info-stealer malware
“This attack is the result of neglecting the security of the RADIUS protocol for too long,” DeKok said. Upgrading to a newer version is essential. Updates are vital to cybersecurity. Malicious users and attackers are constantly looking for new ways to exploit software and applications and cause damage. Updates allow users to address these new threats by installing the necessary protective measures. It is important to apply updates as soon as possible after they are released. Updates contain fixes for known security issues, so delaying their installation can expose your system to risks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
