Pseudo-Random Number Generator Vulnerability in Secomea GateManager Webserver Modules
CVE-2024-1579

Currently unrated

Key Information:

Vendor

Secomea

Vendor
CVE Published:
29 April 2024

What is CVE-2024-1579?

A vulnerability exists in Secomea GateManager's webserver modules that stems from the incorrect use of seeds in its pseudo-random number generator. This misconfiguration can lead to session hijacking, allowing unauthorized users to gain access to valid user sessions. The issue specifically affects versions of GateManager prior to 11.2.624071020, posing significant risks in environments where security is paramount.

References

Timeline

  • Vulnerability published

.