CVE-2013-0294: Fedoraproject Fedora
Medium severity, CVSS 5.9. EPSS: 2.9% chance of exploitation in the next 30 days.
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
Affected products
- Fedoraproject Fedora: version 18 only; version 19 only; version 20 only
- Pyrad Project Pyrad: before 2.1 (fixed in 2.1)
Published 2020-01-28. Last modified 2026-06-16.