An Authentication Bypass by Spoofing vulnerability in RADIUS protocol of Juniper Networks Junos OS, Junos OS Evolved, cRPD and other platforms allows an on-path attacker between RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. This vulnerability depends on using the MD5 hash function to pass undetected attribute forgery by modifying RADIUS server Responses (Access-Accept, Access-Reject, or Access-Challenge). The attacker does not learn user credentials.
It primarily impacts RADIUS implementation using non-EAP authentication methods over UDP. RADIUS/TLS (RadSec) is not susceptible as TLS protects against the attacks. A RADIUS client is vulnerable if it does not require a Message-Authenticator attribute in every server response. It requires an online attack to be able to compute chosen-prefix MD5 collision attack in a time less than the configured radius (round-trip) timeout.
Devices that are not configured with Radius Authentication are not affected by this issue.
Vulnerability impact varies based on the mix of infrastructure devices (RADIUS clients), RADIUS servers and protocols implemented as follows:
Affected implementations are:
Unaffected implementations include:
For additional information regarding this vulnerability, please see https://blastradius.fail.
Based on our current analysis the following products are vulnerable to the issue described in CVE-2024-3596:
Versions of cRPD prior to 23.4 are unaffected by this vulnerability.For Mist products and Services:
Based on our current analysis the following Juniper Networks products are not affected by CVE-2024-3596 issue:
The following products are under analysis and may be affected by CVE-2024-3596 issue:
We continue to evaluate products and this advisory will be updated as further information becomes available.
This issue was discovered during external security research.
This issue has been assigned CVE-2024-3596.
To be exposed to this issue, RADIUS authentication must be enabled on the device.For Junos OS and Junos OS Evolved, the following configuration will enable RADIUS authentication:Administrative Access: [system radius-server] [system authentication-order radius]Subscriber Access: [access profile <name> radius-server]
The following software releases have been updated to resolve this specific issue for RADIUS administrative accessJunos OS: 21.4R3-S9*, 22.2R3-S5*, 22.4R3-S5*, 23.2R2-S3*, 23.4R2-S3*, 24.2R2*, 24.4R1* and all subsequent releases.Junos OS Evolved: 21.4R3-S9-EVO*, 22.2R3-S5-EVO*, 22.4R3-S5-EVO*, 23.2R2-S3-EVO*, 23.4R2-S3-EVO*, 24.2R1-S2-EVO*, 24.2R2-EVO*, 24.4R1-EVO* and all subsequent releases.cRPD: 23.4R2-S3*, 24.2R2*, 24.4R1* and all subsequent releases.*future releaseNote: The fix for RADIUS subscriber access is published as a separate JSA100056 [juniper.net].
This issue is being tracked as 1802329, 1826678 and 1850776 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Enabling RADIUS over TLS (RADSEC) will mitigate this issue. RADIUS clients and servers configured to use DTLS or TLS over TCP are not exploitable, even if the underlying implementation is otherwise vulnerable, as long as the traffic is not sent in plaintext.
• 2024-09-30: Initial Publication • 2024-10-01: Corrected CVSS v4.0 score • 2024-10-03: Modified Workaround and added Acknowledgements• 2024-10-16: changed cRPD affected version from "23.4R3-S5" to "23.4R2-S3"• 2024-10-30: Added Junos OS and Junos OS Evolved Radius authentication config and note on separate PR for Radius Subscriber access2025-07-15: Added the JSA100056 for Radius Subscriber access