Description

Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.

INFO

Published Date :

2026-03-05T02:18:25.951Z

Last Modified :

2026-03-05T16:41:19.727Z

Source :

CPANSec
AFFECTED PRODUCTS

The following products are affected by CVE-2024-57854 vulnerability.

Vendors Products
Dougdude
  • Net::nsca::client
  • Net\

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact