Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37235 | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive. |
Wed, 18 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware |
|
| CPEs | cpe:2.3:h:zyxel:gs1900-10hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-16:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24ep:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8hp:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel
Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware |
Tue, 10 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive. | |
| Weaknesses | CWE-331 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2024-09-10T15:15:34.477Z
Reserved: 2024-06-12T09:11:12.898Z
Link: CVE-2024-38270
Updated: 2024-09-10T15:15:18.502Z
Status : Analyzed
Published: 2024-09-10T02:15:09.780
Modified: 2024-09-18T18:23:40.977
Link: CVE-2024-38270
No data.
OpenCVE Enrichment
No data.
EUVD