CVE-2024-3596 / Radius client msg authenticator attribute
- 
 Hello, as far as I can gather the mitigation for CVE-2024-3596 needs to be done on the radius client site; in my case pfSense. I did turn on the requirement in Windows NPS: 
  
 Everything still seems to work well so far.Can someone tell me whether or not the attribute should be in all of pfSense's Radius-requests by default? (I did not find any setting) 
 Thanks,
- 
 If you have set that I would expect no issue since the server would reject any unauthenticated requests. 
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
