Researchers disclosed Blast-RADIUS, a protocol-level weakness in RADIUS tracked as CVE-2024-3596, that allows a man-in-the-middle attacker to tamper with authentication exchanges and convert a legitimate Access-Reject or other server response into a forged Access-Accept. The issue stems from insecure practices in RADIUS defined in RFC 2865, including reliance on an MD5-based Response Authenticator and insufficient integrity protection for Access-Request packets. Public reporting and vendor advisories indicate the attack can let an adversary bypass authentication without knowing user passwords or shared secrets, creating a path to unauthorized network access and potential compromise of administrative interfaces on affected infrastructure.
The vulnerability has prompted broad industry response, with advisories and analysis from vendors and security organizations including Cloudflare, CERT/CC, Siemens, NetApp, SonicWall, and CISA-linked ICS guidance, alongside IETF work on deprecating insecure RADIUS practices. Recommended mitigations include updating affected products and enforcing the Message-Authenticator attribute on all RADIUS requests and responses, with Access-Accept and Access-Reject placing that attribute first, while organizations review deployments that still depend on legacy UDP-based RADIUS protections.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The IETF RADext working group published a draft focused on deprecating insecure practices in RADIUS in response to protocol weaknesses highlighted by BlastRADIUS. This reflects a standards-level effort to address the insecure legacy behavior in RADIUS deployments.
Public guidance and advisories were issued describing mitigations for BlastRADIUS, including firmware updates and enforcing the Message-Authenticator attribute on requests and responses. The Tenable reference also notes multiple vendor advisories and CERT/CC and CISA-linked materials covering affected products and mitigations.
Researchers disclosed BlastRADIUS, a forgery attack against the RADIUS authentication protocol tracked as CVE-2024-3596. The issue stems from weaknesses in RFC 2865 RADIUS, including MD5-based response authentication and insufficient integrity protection, enabling a man-in-the-middle attacker to turn a valid server response into a forged one.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceblastradius.fail
Open sourcedatatracker.ietf.org
Open sourcetenable.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.