PT-2024-31748 · Tgt+3 · Tgt+3
David Gstir
+1
·
Published
2024-09-05
·
Updated
2026-05-27
·
CVE-2024-45751
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
tgt versions prior to 1.0.93
Description:
The issue is related to the Linux target framework (tgt) attempting to generate random numbers by using
rand without srand, resulting in a predictable PRNG seed. This causes the sequence of challenges to be always identical. An attacker capable of recording network traffic can abuse this by replaying previous responses, potentially leading to a CHAP authentication bypass.Recommendations:
For versions prior to 1.0.93, update to version 1.0.93 or later to resolve the issue. As a temporary workaround, consider restricting access to the tgt framework until a patch is applied. Avoid using the tgt framework for authentication until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Suse
Ubuntu
Tgt