An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 18 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Zyxel Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware | |
| CPEs | cpe:2.3:h:zyxel:gs1900-10hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-16:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24ep:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-24hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-48hpv2:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:gs1900-8hp:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Zyxel Zyxel gs1900-10hp Zyxel gs1900-10hp Firmware Zyxel gs1900-16 Zyxel gs1900-16 Firmware Zyxel gs1900-24 Zyxel gs1900-24 Firmware Zyxel gs1900-24e Zyxel gs1900-24e Firmware Zyxel gs1900-24ep Zyxel gs1900-24ep Firmware Zyxel gs1900-24hpv2 Zyxel gs1900-24hpv2 Firmware Zyxel gs1900-48 Zyxel gs1900-48 Firmware Zyxel gs1900-48hpv2 Zyxel gs1900-48hpv2 Firmware Zyxel gs1900-8 Zyxel gs1900-8 Firmware Zyxel gs1900-8hp Zyxel gs1900-8hp Firmware | 
Tue, 10 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 10 Sep 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive. | |
| Weaknesses | CWE-331 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Zyxel
Published: 2024-09-10T01:20:09.147Z
Updated: 2024-09-10T15:15:34.477Z
Reserved: 2024-06-12T09:11:12.898Z
Link: CVE-2024-38270
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-09-10T15:15:18.502Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-09-10T02:15:09.780
Modified: 2024-09-18T18:23:40.977
Link: CVE-2024-38270
 Redhat
                        Redhat
                    No data.