VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2163

CVE-2004-2163

Description

The login_radius program on OpenBSD fails to verify the RADIUS server's shared secret, allowing remote attackers to spoof server replies and bypass authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The login_radius program on OpenBSD fails to verify the RADIUS server's shared secret, allowing remote attackers to spoof server replies and bypass authentication.

Vulnerability

The login_radius program in OpenBSD (versions 3.2, 3.5, and possibly others) does not validate the shared secret in RADIUS authentication response packets. This flaw allows the program to accept spoofed replies from an attacker without proper verification, bypassing intended RADIUS security controls.

Exploitation

An attacker with network access to the victim's RADIUS infrastructure can send crafted RADIUS Access-Accept packets that are accepted without a valid shared secret. No prior authentication is needed. The attacker simply spoofs a legitimate RADIUS server's response during the authentication process.

Impact

Successful exploitation allows the attacker to bypass authentication checks, gaining unauthorized access to network resources or services that rely on RADIUS for authentication. This effectively undermines access control, potentially leading to full compromise of affected systems.

Mitigation

OpenBSD released a security patch for this issue, available in the OpenBSD 3.5 errata [1]. Systems running affected versions should apply the patch or update to a fixed release. No workaround is documented; patching is recommended.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • OpenBSD/OpenBSD3 versions
    cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:*
    • cpe:2.3:o:openbsd:openbsd:3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:openbsd:openbsd:3.5:*:*:*:*:*:*:*
  • Range: 3.2, 3.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.