PT-2026-23125 · Unknown · Crypt::Random+2

Robert Rothenberg

·

Published

2026-03-05

·

Updated

2026-03-09

·

CVE-2024-57854

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Net::NSCA::Client versions through 0.009002
Description Net::NSCA::Client for Perl utilizes an inadequate random number generator. Version 0.003 transitioned to using Data::Rand::Obscure instead of Crypt::Random for generating initialization vectors. Data::Rand::Obscure relies on Perl's built-in rand() function, which is not appropriate for cryptographic applications.
Recommendations Versions prior to 0.009002 should be updated.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-57854

Affected Products

Crypt::Random
Data::Rand::Obscure
Net::Nsca::Client