Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38vv-qgw3-86p8

Опубликовано: 10 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-331