CVE-2024-28957
MEDIUMDescription
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
Is your site exposed to CVE-2024-28957?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nxtech | cente_ipv6 |
| nxtech | cente_ipv6_snmpv2 |
| nxtech | cente_ipv6_snmpv3 |
| nxtech | cente_tcp\/ipv4 |
| nxtech | cente_tcp\/ipv4_snmpv2 |
| nxtech | cente_tcp\/ipv4_snmpv3 |
References
Frequently Asked Questions
What is CVE-2024-28957? +
How severe is CVE-2024-28957? +
What products are affected by CVE-2024-28957? +
How do I check if I'm vulnerable to CVE-2024-28957? +
Related Vulnerabilities
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due …
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation …
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs …
Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with …
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using …