CVE-2024-3596 / Radius client msg authenticator attribute
-
Hello,
as far as I can gather the mitigation for CVE-2024-3596 needs to be done on the radius client site; in my case pfSense.
I did turn on the requirement in Windows NPS:
Everything still seems to work well so far.Can someone tell me whether or not the attribute should be in all of pfSense's Radius-requests by default? (I did not find any setting)
Thanks, -
If you have set that I would expect no issue since the server would reject any unauthenticated requests.