PT-2024-31748 · Tgt+3 · Tgt+3

David Gstir

+1

·

Published

2024-09-05

·

Updated

2026-05-27

·

CVE-2024-45751

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: tgt versions prior to 1.0.93
Description: The issue is related to the Linux target framework (tgt) attempting to generate random numbers by using rand without srand, resulting in a predictable PRNG seed. This causes the sequence of challenges to be always identical. An attacker capable of recording network traffic can abuse this by replaying previous responses, potentially leading to a CHAP authentication bypass.
Recommendations: For versions prior to 1.0.93, update to version 1.0.93 or later to resolve the issue. As a temporary workaround, consider restricting access to the tgt framework until a patch is applied. Avoid using the tgt framework for authentication until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-45751
DLA-3976-1
MGASA-2024-0304
OESA-2024-2156
SUSE-SU-2025:02591-1
SUSE-SU-2025:02740-1
SUSE-SU-2025_02740-1
USN-7024-1
USN-8325-1

Affected Products

Linuxmint
Suse
Ubuntu
Tgt