RADIUS: Malformed Vendor-Specific Attribute

This protocol anomaly is a RADIUS vendor length that is less than 2, or the sum of all vendor lengths is not equal to length of the Vendor-Specific attribute minus 6. According to the RADIUS RFC, if a Vendor specific string is longer than or equal to 2 bytes, it should be encoded as a sequence of vendor type / vendor length / value fields, where vendor type and length both are eight bit long. The vendor lengths should not be less than 2. The sum of all vendor lengths should be equal to length of the Vendor-Specific attribute minus 6 (6 is the sum of the lengths of other fields including type, length, and vendor id).

Short Name
RADIUS:MALFORMED_VENDOR_ATTR
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
RADIUS
Keywords
CVE-2017-10979 bid:99901
Release Date
01/30/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?