CVE-2024-10604Use of Insufficiently Random Values in Google Fuchsia

Severity
6.9MEDIUMNVD
EPSS
0.1%
top 71.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30

Description

Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Packages1 packages

NVDgoogle/fuchsiaf17f20+1

Patches

🔴Vulnerability Details

2
CVEList
Identifiable Header Values In Fuchsia Leading To Tracking of The User2025-01-30
GHSA
GHSA-mhfq-8c27-vp58: Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP sou2025-01-30
CVE-2024-10604 — Use of Insufficiently Random Values | cvebase