CVE-2024-38270
CVSS V2 None
CVSS V3 None
Description
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
Overview
- CVE ID
- CVE-2024-38270
- Assigner
- Zyxel
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-10T01:20:09.147Z
- Last Modified Date
- 2024-09-10T01:20:09.147Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-38270 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38270 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-09-10 13:14:03 | Added to TrackCVE |