Insufficient Entropy Vulnerability in Zyxel GS1900-10HP Firmware Could Allow LAN-Based Attackers to Gain Valid Session Token

CVE-2024-38270

6.5MEDIUM

Key Information

Vendor
Zyxel
Status
Gs1900-10HP Firmware
Vendor
CVE Published:
10 September 2024

Summary

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

Affected Version(s)

GS1900-10HP firmware V2.80(AAZI.0)C0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre Database
.