CVE

Id
10589  
CVE No.
CVE-2004-2163  
Status
Candidate  
Description
login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.  
Phase
Assigned (20050710)  
Votes
None (candidate not yet proposed)  
Comments