CVE-2022-41859: Infoleak
Published Jan 17, 2023
·Updated
In freeradius, the EAP-PWD function computepasswordelement() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
Affected Software
1 affected component
FreeRADIUS freeradius<3.0.0
Remediation
Patch Available
Event History
Jan 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-41859?
CVE-2022-41859 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-41859?
To fix CVE-2022-41859, upgrade FreeRADIUS to version 3.0.0 or later.
3
What component is affected by CVE-2022-41859?
CVE-2022-41859 affects the EAP-PWD function in FreeRADIUS.
4
What type of attack does CVE-2022-41859 facilitate?
CVE-2022-41859 allows attackers to reduce the time needed for an offline dictionary attack.
5
What information is leaked due to CVE-2022-41859?
CVE-2022-41859 leaks information about user passwords.