CVE-2024-3596: exploitation status and patch state
CVE-2024-3596 · CVSS 9.0 CRITICAL · EPSS 15%
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Is CVE-2024-3596 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 15%.
Public exploit code: none found in monitored sources.