Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Oracle Linux: CVE-2019-13456: ELSA-2020-1672: freeradius:3.0 security update (MODERATE) (Multiple Advisories)

Severity
3
CVSS
(AV:A/AC:M/Au:N/C:P/I:N/A:N)
Published
Aug 3, 2019
Added
Oct 7, 2020
Modified
Dec 4, 2025

Description

In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
An information leak was discovered in the implementation of EAP-pwd in freeradius. An attacker could initiate several EAP-pwd handshakes to leak information, which can then be used to recover the user's WiFi password by performing dictionary and brute-force attacks.

Solutions

oracle-linux-upgrade-freeradiusoracle-linux-upgrade-freeradius-develoracle-linux-upgrade-freeradius-docoracle-linux-upgrade-freeradius-krb5oracle-linux-upgrade-freeradius-ldaporacle-linux-upgrade-freeradius-mysqloracle-linux-upgrade-freeradius-perloracle-linux-upgrade-freeradius-postgresqloracle-linux-upgrade-freeradius-pythonoracle-linux-upgrade-freeradius-restoracle-linux-upgrade-freeradius-sqliteoracle-linux-upgrade-freeradius-unixodbcoracle-linux-upgrade-freeradius-utils
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.