CVE-2004-2163
Description
The login_radius program on OpenBSD fails to verify the RADIUS server's shared secret, allowing remote attackers to spoof server replies and bypass authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The login_radius program on OpenBSD fails to verify the RADIUS server's shared secret, allowing remote attackers to spoof server replies and bypass authentication.
Vulnerability
The login_radius program in OpenBSD (versions 3.2, 3.5, and possibly others) does not validate the shared secret in RADIUS authentication response packets. This flaw allows the program to accept spoofed replies from an attacker without proper verification, bypassing intended RADIUS security controls.
Exploitation
An attacker with network access to the victim's RADIUS infrastructure can send crafted RADIUS Access-Accept packets that are accepted without a valid shared secret. No prior authentication is needed. The attacker simply spoofs a legitimate RADIUS server's response during the authentication process.
Impact
Successful exploitation allows the attacker to bypass authentication checks, gaining unauthorized access to network resources or services that rely on RADIUS for authentication. This effectively undermines access control, potentially leading to full compromise of affected systems.
Mitigation
OpenBSD released a security patch for this issue, available in the OpenBSD 3.5 errata [1]. Systems running affected versions should apply the patch or update to a fixed release. No workaround is documented; patching is recommended.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: 3.2, 3.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/12617nvdPatchVendor Advisory
- www.openbsd.org/errata35.htmlnvdPatch
- www.reseau.nl/advisories/0400-openbsd-radius.txtnvdPatchVendor Advisory
- www.securityfocus.com/bid/11227nvdPatch
- archives.neohapsis.com/archives/vulnwatch/2004-q3/0058.htmlnvdVendor Advisory
- www.osvdb.org/10203nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17456nvd
News mentions
0No linked articles in our index yet.