PT-2024-31748 · Tgt+3 · Tgt+3

·

CVE-2024-45751

·

Published

2024-09-05

·

Updated

2026-05-27

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: tgt versions prior to 1.0.93
Description: The issue is related to the Linux target framework (tgt) attempting to generate random numbers by using rand without srand, resulting in a predictable PRNG seed. This causes the sequence of challenges to be always identical. An attacker capable of recording network traffic can abuse this by replaying previous responses, potentially leading to a CHAP authentication bypass.
Recommendations: For versions prior to 1.0.93, update to version 1.0.93 or later to resolve the issue. As a temporary workaround, consider restricting access to the tgt framework until a patch is applied. Avoid using the tgt framework for authentication until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45751
DLA-3976-1
MGASA-2024-0304
OESA-2024-2156
SUSE-SU-2025:02591-1
SUSE-SU-2025:02740-1
SUSE-SU-2025_02740-1
USN-7024-1
USN-8325-1

Affected Products

Linuxmint
Suse
Ubuntu
Tgt