CVE-2024-3596: Broadcom Brocade Sannav

Critical severity, CVSS 9.0. EPSS: 14.9% chance of exploitation in the next 30 days.

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Affected products

  • Broadcom Brocade Sannav: affected versions not specified
  • Broadcom Fabric Operating System: affected versions not specified
  • Freeradius Freeradius: before 3.0.27 (fixed in 3.0.27)
  • SonicWall SonicOS: affected versions not specified

Published 2024-07-09. Last modified 2026-06-17.