Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
radsecproxy 客户端证书验证安全绕过漏洞
Vulnerability Description
Radsecproxy是一款通用RADIUS代理,支持RADIUS UDP和TLS (RadSec)。 radsecproxy 1.6.2之前版本中的DTLS支持中存在漏洞,该漏洞源于配置块以被用于验证证书链的块无关的CA设置时,没有正确验证证书。远程攻击者利用该漏洞绕过目地访问限制并欺骗客户端。
CVSS Information
N/A
Vulnerability Type
N/A