Description

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

INFO

Published Date :

2024-09-10T01:20:09.147Z

Last Modified :

2024-09-10T15:15:34.477Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2024-38270 vulnerability.

Vendors Products
Zyxel
  • Gs1900-10hp
  • Gs1900-10hp Firmware
  • Gs1900-16
  • Gs1900-16 Firmware
  • Gs1900-24
  • Gs1900-24 Firmware
  • Gs1900-24e
  • Gs1900-24e Firmware
  • Gs1900-24ep
  • Gs1900-24ep Firmware
  • Gs1900-24hpv2
  • Gs1900-24hpv2 Firmware
  • Gs1900-48
  • Gs1900-48 Firmware
  • Gs1900-48hpv2
  • Gs1900-48hpv2 Firmware
  • Gs1900-8
  • Gs1900-8 Firmware
  • Gs1900-8hp
  • Gs1900-8hp Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact