PT-2025-1323 · Unknown · Net::Easytcp
Published
2025-01-02
·
Updated
2025-01-02
·
CVE-2002-20002
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Net::EasyTCP versions prior to 0.15
Description
The issue concerns the use of Perl's built-in
rand() function, which is not a strong random number generator, for generating cryptographic keys. This weakness can potentially lead to predictable keys.Recommendations
For versions prior to 0.15, consider updating to version 0.15 or later to address the issue with the random number generator used for cryptographic keys. As a temporary workaround, consider implementing an alternative, cryptographically secure random number generator for key generation until the update can be applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Easytcp