PT-2025-1599 · Google · Fuchsia

Amit Klein

+3

·

Publicado

2025-01-30

·

Atualizado

2025-07-29

·

CVE-2024-10604

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Fuchsia (affected versions not specified)
Description The issue concerns vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields. Specifically, the vulnerabilities affect the TCP Initial Sequence Number (ISN), TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID. These vulnerabilities allow for the values to be guessed under certain circumstances.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-10604

Produtos afetados

Fuchsia