An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zyxel
Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware |
|
CPEs | cpe:2.3:h:zyxel:gs1900-10hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-16:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24ep:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8hp:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Zyxel
Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware |
Tue, 10 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive. | |
Weaknesses | CWE-331 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Zyxel
Published: 2024-09-10T01:20:09.147Z
Updated: 2024-09-10T15:15:34.477Z
Reserved: 2024-06-12T09:11:12.898Z
Link: CVE-2024-38270
Vulnrichment
Updated: 2024-09-10T15:15:18.502Z
NVD
Status : Analyzed
Published: 2024-09-10T02:15:09.780
Modified: 2024-09-18T18:23:40.977
Link: CVE-2024-38270
Redhat
No data.