CVE-2017-9148: Freeradius

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

Affected products

  • Freeradius Freeradius: version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; version 2.1.6 only; version 2.1.7 only; …

Published 2017-05-29. Last modified 2026-06-17.