PT-2025-1599 · Google · Fuchsia

Amit Klein

+3

·

Published

2025-01-30

·

Updated

2025-07-29

·

CVE-2024-10604

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Fuchsia (affected versions not specified)
Description The issue concerns vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields. Specifically, the vulnerabilities affect the TCP Initial Sequence Number (ISN), TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID. These vulnerabilities allow for the values to be guessed under certain circumstances.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2024-10604

Affected Products

Fuchsia